Weeks after go-live, the initial service port still carries the temporary addressing used during installation, and no one documented any decision about it. What is the correct treatment of the service port at the end of the network configuration work?
Select an answer to reveal the explanation.
Short Explanation
Temporary things have a way of outliving the people who meant to fix them. That install-day service-port addressing you left in place is now production — it's just production nobody documented. Make a deliberate call — keep it on purpose, disable it, or reserve it for emergencies — and write the decision down, because undocumented state is how an open door stays open.
Full Explanation
The service port is an installation instrument with a real presence on the network, and a temporary state left running on a production system is an undocumented, unmanaged access path. Correct treatment at the end of network configuration is an explicit, recorded decision: keep it addressed deliberately under the customer's support model, disable it, or hold it secured for break-glass — with the chosen state documented so the next engineer inherits a decision rather than a mystery. Never-alter claims fail by mechanism: the port is configurable like any interface, and its legitimate support purposes argue for a designed state, not for fossilized install-day addressing. Blanket removal overreaches in the opposite direction — support engagements and break-glass scenarios can legitimately require the console-equivalent path, and a policy that deletes the capability converts future necessity into a recovery project. Bridging it onto the management VLAN inverts the separation logic: it fuses the emergency path with daily operations and doubles exposure on both sides while creating address conflicts the design never sanctioned. Temporary configurations that are never reviewed become invisible to audits and indistinguishable from intended architecture — until an incident. Exam caveat: whichever state is chosen, the runbook must state how the port returns to service for support work and who authorizes that. Operational check: list the service port's state and addressing at handover, confirm it matches the documented decision, and record the break-glass activation steps in the runbook.