An administrator makes an unapproved firewall rule change directly on a production server outside of the organization's standard request-and-approval workflow. The change causes an unexpected outage for a critical application. Which process failure most directly contributed to this incident?
- ALack of patch management
- BLack of change management
- CLack of vulnerability management
- DLack of asset management
Show answer & explanationAnswer & explanation
Correct answer: B. Lack of change management
Change management requires that modifications to production systems go through a formal request, review, approval, and rollback-planning process to prevent unintended impacts; bypassing this process directly caused the outage. Asset management tracks inventory of devices, patch management addresses applying vendor updates, and vulnerability management focuses on identifying and remediating weaknesses—none of these govern the approval workflow for configuration changes.
Why the other options are wrong
- A. Patch management concerns applying vendor updates, not ad hoc rule changes.
- C. Vulnerability management identifies weaknesses, not unauthorized configuration changes.
- D. Asset management tracks what assets exist, not approval of changes made to them.
Change Management
A formal process requiring review, approval, testing, and documentation before changes are made to production systems, reducing the risk of unintended outages.
- Includes a Change Advisory Board (CAB) in many orgs
- Requires rollback plans for failed changes
- Bypassing it is a common root cause of outages
Memory trick: Skipping change management is like performing surgery without checking the chart first.