CAS-001 · Question #269
When Company A and Company B merged, the network security administrator for Company A was tasked with joining the two networks. Which of the following should be done FIRST?
The correct answer is C. Perform a vulnerability assessment on Company B's network. Before connecting two separate networks, the security administrator must understand the security posture of the network being merged in. A vulnerability assessment is the appropriate first step - it is a non-invasive, systematic review that identifies weaknesses…
Question
When Company A and Company B merged, the network security administrator for Company A was tasked with joining the two networks. Which of the following should be done FIRST?
Options
- AImplement a unified IPv6 addressing scheme on the entire network.
- BConduct a penetration test of Company B's network.
- CPerform a vulnerability assessment on Company B's network.
- DPerform a peer code review on Company B's application.
How the community answered
(21 responses)- A5% (1)
- B10% (2)
- C81% (17)
- D5% (1)
Explanation
Before connecting two separate networks, the security administrator must understand the security posture of the network being merged in. A vulnerability assessment is the appropriate first step - it is a non-invasive, systematic review that identifies weaknesses, misconfigurations, and risks in Company B's environment. This information is critical before any integration decision is made. A penetration test (B) is more invasive and typically comes after a vulnerability assessment, once scope and risk are understood. Implementing IPv6 (A) is an infrastructure task, not a security assessment. A code review (D) is scoped only to applications and misses network, host, and configuration vulnerabilities.
Topics
Community Discussion
No community discussion yet for this question.