CAS-002 · Question #101
A systems security consultant is hired by Corporation X to analyze the current enterprise network environment and make recommendations for increasing network security. It is the consultant's first…
The correct answer is B. What corporate assets need to be protected? C. What are the business needs of the organization? D. What outside threats are most likely to compromise network security? On day one, a consultant must establish what assets require protection, what the business needs, and what threats are most relevant before recommending any solutions.
Question
A systems security consultant is hired by Corporation X to analyze the current enterprise network environment and make recommendations for increasing network security. It is the consultant's first day on the job. Which of the following network design considerations should the consultant consider? (Select THREE).
Options
- AWhat hardware and software would work best for securing the network?
- BWhat corporate assets need to be protected?
- CWhat are the business needs of the organization?
- DWhat outside threats are most likely to compromise network security?
- EWhat is the budget for this project?
- FWhat time and resources are needed to carry out the security plan?
How the community answered
(40 responses)- A8% (3)
- B80% (32)
- E3% (1)
- F10% (4)
Why each option
On day one, a consultant must establish what assets require protection, what the business needs, and what threats are most relevant before recommending any solutions.
Recommending specific hardware and software is premature before assets, threats, and business context are fully understood - solutions must follow analysis, not precede it.
Identifying corporate assets defines the scope of what the security architecture must protect, which is the essential starting point for any network security analysis.
Understanding business needs ensures that security recommendations align with operational requirements and do not block legitimate workflows or revenue-generating activities.
Enumerating the most likely outside threats focuses the analysis on realistic risk scenarios and directs attention toward the controls that will have the greatest impact.
Budget is a project management and procurement constraint, not a network design consideration to evaluate during initial security analysis.
Estimating time and resources for execution is a project planning activity, separate from the network design analysis that informs what needs to be done.
Concept tested: Network security assessment initial scoping and requirements gathering
Source: https://csrc.nist.gov/publications/detail/sp/800-100/final
Topics
Community Discussion
No community discussion yet for this question.