nerdexam
CompTIA

CAS-001 · Question #269

When Company A and Company B merged, the network security administrator for Company A was tasked with joining the two networks. Which of the following should be done FIRST?

The correct answer is C. Perform a vulnerability assessment on Company B's network. Before connecting two separate networks, the security administrator must understand the security posture of the network being merged in. A vulnerability assessment is the appropriate first step - it is a non-invasive, systematic review that identifies weaknesses…

Research and Analysis

Question

When Company A and Company B merged, the network security administrator for Company A was tasked with joining the two networks. Which of the following should be done FIRST?

Options

  • AImplement a unified IPv6 addressing scheme on the entire network.
  • BConduct a penetration test of Company B's network.
  • CPerform a vulnerability assessment on Company B's network.
  • DPerform a peer code review on Company B's application.

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    81% (17)
  • D
    5% (1)

Explanation

Before connecting two separate networks, the security administrator must understand the security posture of the network being merged in. A vulnerability assessment is the appropriate first step - it is a non-invasive, systematic review that identifies weaknesses, misconfigurations, and risks in Company B's environment. This information is critical before any integration decision is made. A penetration test (B) is more invasive and typically comes after a vulnerability assessment, once scope and risk are understood. Implementing IPv6 (A) is an infrastructure task, not a security assessment. A code review (D) is scoped only to applications and misses network, host, and configuration vulnerabilities.

Topics

#vulnerability assessment#network merger#due diligence#penetration testing

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice