nerdexam
CompTIA

CAS-001 · Question #318

The lead systems architect on a software development project developed a design which is optimized for a distributed computing environment. The security architect assigned to the project has…

The correct answer is C. Document mitigations to the security concerns and facilitate a meeting between the architects and. Answer C is correct because it addresses both problems simultaneously: documenting mitigations handles the technical security concern professionally and creates an audit trail, while facilitating a meeting between the security architect and systems architect resolves the root…

Integration of Computing, Communications and Business Disciplines

Question

The lead systems architect on a software development project developed a design which is optimized for a distributed computing environment. The security architect assigned to the project has concerns about the integrity of the system, if it is deployed in a commercial cloud. Due to poor communication within the team, the security risks of the proposed design are not being given any attention. A network engineer on the project has a security background and is concerned about the overall success of the project. Which of the following is the BEST course of action for the network engineer to take?

Options

  • AAddress the security concerns through the network design and security controls.
  • BImplement mitigations to the security risks and address the poor communications on the team with
  • CDocument mitigations to the security concerns and facilitate a meeting between the architects and
  • DDevelop a proposal for an alternative architecture that does not leverage cloud computing and present

How the community answered

(27 responses)
  • A
    26% (7)
  • B
    7% (2)
  • C
    56% (15)
  • D
    11% (3)

Explanation

Answer C is correct because it addresses both problems simultaneously: documenting mitigations handles the technical security concern professionally and creates an audit trail, while facilitating a meeting between the security architect and systems architect resolves the root communication breakdown. This approach is collaborative rather than unilateral and respects the proper roles of each team member. Answer A only addresses the technical dimension through network controls, ignoring the communication failure that will allow risks to recur. Answer B (implementing mitigations without coordination) oversteps the network engineer's authority and bypasses the architects. Answer D (proposing an alternative architecture) is outside the network engineer's scope, dismisses cloud requirements without proper authority, and does not address the communication problem.

Topics

#security governance#risk communication#cloud security#stakeholder management

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice