CAS-001 · Question #103
Existing enterprise architecture included an enclave where sensitive research and development work was conducted. This network enclave also served as a storage location for proprietary corporate…
The correct answer is A. Emerging business requirements led to the de-parameterization of the network. De-parameterization refers to the gradual erosion of a well-defined network perimeter as business and operational needs cause users and systems to connect outside the established boundary. Initially, the enclave was fully contained - all traffic flowed through a single…
Question
Existing enterprise architecture included an enclave where sensitive research and development work was conducted. This network enclave also served as a storage location for proprietary corporate data and records. The initial security architect chose to protect the enclave by restricting access to a single physical port on a firewall. All downstream network devices were isolated from the rest of the network and communicated solely through the single 100mbps firewall port. Over time, researchers connected devices on the protected enclave directly to external resources and corporate data stores. Mobile and wireless devices were also added to the enclave to support high speed data research. Which of the following BEST describes the process which weakened the security posture of the enclave?
Options
- AEmerging business requirements led to the de-parameterization of the network.
- BEmerging security threats rendered the existing architecture obsolete.
- CThe single firewall port was oversaturated with network packets.
- DThe shrinking of an overall attack surface due to the additional access.
How the community answered
(38 responses)- A84% (32)
- B3% (1)
- C8% (3)
- D5% (2)
Explanation
De-parameterization refers to the gradual erosion of a well-defined network perimeter as business and operational needs cause users and systems to connect outside the established boundary. Initially, the enclave was fully contained - all traffic flowed through a single controlled firewall port. Over time, business requirements (researchers needing to access external resources, collaboration via mobile and wireless devices) caused the perimeter to dissolve. Connections were made that bypassed the central firewall entirely, eliminating the very protection it was designed to provide. This is not about the firewall becoming obsolete due to new threats (B) - the architecture was deliberately circumvented by users. Option C (port saturation) is a bandwidth/performance concern, not a security one. Option D is factually wrong - the attack surface expanded, it did not shrink.
Topics
Community Discussion
No community discussion yet for this question.