CAS-002 · Question #120
A corporation has expanded for the first time by integrating several newly acquired businesses. Which of the following are the FIRST tasks that the security team should undertake? (Select TWO).
The correct answer is E. Develop interconnection policy. F. Conduct a risk analysis of each acquired company's networks. When integrating newly acquired businesses, the security team must first assess risk and define governance policy before making any technical changes to the combined network environment.
Question
A corporation has expanded for the first time by integrating several newly acquired businesses. Which of the following are the FIRST tasks that the security team should undertake? (Select TWO).
Options
- ARemove acquired companies Internet access.
- BFederate identity management systems.
- CInstall firewalls between the businesses.
- DRe-image all end user computers to a standard image.
- EDevelop interconnection policy.
- FConduct a risk analysis of each acquired company's networks.
How the community answered
(38 responses)- A5% (2)
- B3% (1)
- C16% (6)
- D8% (3)
- E68% (26)
Why each option
When integrating newly acquired businesses, the security team must first assess risk and define governance policy before making any technical changes to the combined network environment.
Removing internet access from acquired companies is an extreme operational disruption and is not a standard first step during acquisition integration.
Federating identity management systems is a later-stage integration task that requires both a completed risk baseline and an interconnection policy to already be in place.
Installing firewalls between businesses is a technical control that must be informed by the interconnection policy and risk analysis, not performed before them.
Re-imaging end user computers is a remediation action that logically follows a risk assessment identifying the need, not a first-priority task.
Developing an interconnection policy establishes the rules, requirements, and conditions governing how the acquired companies' networks will be linked to the corporate network, which must exist before any integration activity begins.
Conducting a risk analysis of each acquired company's networks identifies existing vulnerabilities, misconfigurations, and threat vectors that could expose the corporate infrastructure before interconnection occurs.
Concept tested: Security priorities for integrating acquired business networks
Source: https://csrc.nist.gov/publications/detail/sp/800-47/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.