CAS-001 · Question #443
The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The CEO argues that…
The correct answer is B. The aggregation of employees on a corporate network makes it a more valuable target for. The CEO's argument conflates individual risk with aggregate risk. While it is true that home networks are outside corporate control, the corporate network aggregates hundreds or thousands of employees, systems, and sensitive resources into a single environment. This…
Question
The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The CEO argues that the company cannot protect its employees at home, so the risk at work is no different. Which of the following BEST explains why this company should proceed with protecting its corporate network boundary?
Options
- AThe corporate network is the only network that is audited by regulators and customers.
- BThe aggregation of employees on a corporate network makes it a more valuable target for
- CHome networks are unknown to attackers and less likely to be targeted directly.
- DEmployees are more likely to be using personal computers for general web browsing when they
How the community answered
(47 responses)- A4% (2)
- B85% (40)
- C9% (4)
- D2% (1)
Explanation
The CEO's argument conflates individual risk with aggregate risk. While it is true that home networks are outside corporate control, the corporate network aggregates hundreds or thousands of employees, systems, and sensitive resources into a single environment. This concentration makes it an exponentially more attractive and valuable target for adversaries - a successful breach yields access to the entire organization, not just one employee. The aggregation of high-value assets and privileged access on the corporate network (B) justifies a disproportionately stronger defensive investment compared to any single home network. Regulatory auditing (A) is a compliance reason, not a primary security rationale. Home networks being 'unknown to attackers' (C) is false - home networks are regularly targeted. Personal computer usage at home (D) is a separate endpoint risk issue unrelated to why the corporate perimeter should be hardened.
Topics
Community Discussion
No community discussion yet for this question.