nerdexam
ExamsCAS-001Questions#390
CompTIA

CAS-001 · Question #390

CAS-001 Question #390: Real Exam Question with Answer & Explanation

The correct answer is A: How the large business operational procedures are implemented.. During a post-acquisition IT integration, the smaller business's IT staff must adapt to the acquiring organization's environment and new legal obligations. Option A is critical because staff retaining their jobs must understand and align with the large business's operational proc

Question

A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have agreed that the large business will retain 95% of the smaller business' IT staff. Additionally, the larger business has a strong interest in specific processes that the smaller business has in place to handle its regional interests. Which of the following IT security related objectives should the small business' IT staff consider reviewing during the integration process? (Select TWO).

Options

  • AHow the large business operational procedures are implemented.
  • BThe memorandum of understanding between the two businesses.
  • CNew regulatory compliance requirements.
  • DService level agreements between the small and the large business.
  • EThe initial request for proposal drafted during the merger.
  • FThe business continuity plan in place at the small business.

Explanation

During a post-acquisition IT integration, the smaller business's IT staff must adapt to the acquiring organization's environment and new legal obligations. Option A is critical because staff retaining their jobs must understand and align with the large business's operational procedures - including security policies, access control models, incident response workflows, and change management processes. Option C is critical because the combined entity may now operate in new jurisdictions or cross regulatory thresholds (e.g., revenue, employee count, geographic footprint) that impose new compliance requirements such as GDPR, PCI-DSS, HIPAA, or SOX. The MOU (B) and SLA (D) govern the business relationship but are not direct IT security concerns for operational staff. The RFP (E) is a pre-acquisition document with no post-integration relevance. The small business's BCP (F) would be superseded by the acquiring organization's BCP, so reviewing it does not serve the integration objective.

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice