nerdexam
CompTIA

CAS-002 · Question #252

A new internal network segmentation solution will be implemented into the enterprise that consists of 200 internal firewalls. As part of running a pilot exercise, it was determined that it takes…

The correct answer is D. Review to determine if control effectiveness is in line with the complexity of the solution. When security controls introduce significant operational complexity - such as requiring three change requests per application deployment across 200 firewalls - the first step is to evaluate whether the control's effectiveness justifies that complexity.

Enterprise Security

Question

A new internal network segmentation solution will be implemented into the enterprise that consists of 200 internal firewalls. As part of running a pilot exercise, it was determined that it takes three changes to deploy a new application onto the network before it is operational. Security now has a significant affect on overall availability. Which of the following would be the FIRST process to perform as a result of these findings?

Options

  • ALower the SLA to a more tolerable level and perform a risk assessment to see if the solution
  • BPerform a cost benefit analysis and implement the solution as it stands as long as the risks
  • CEngage internal auditors to perform a review of the project to determine why and how the
  • DReview to determine if control effectiveness is in line with the complexity of the solution.

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    23% (5)
  • C
    9% (2)
  • D
    64% (14)

Why each option

When security controls introduce significant operational complexity - such as requiring three change requests per application deployment across 200 firewalls - the first step is to evaluate whether the control's effectiveness justifies that complexity.

ALower the SLA to a more tolerable level and perform a risk assessment to see if the solution

Lowering the SLA before understanding whether the controls are even effective is premature and could lock the organization into accepting reduced availability without confirming any security benefit.

BPerform a cost benefit analysis and implement the solution as it stands as long as the risks

Performing a cost-benefit analysis before confirming whether the controls actually work as intended produces unreliable conclusions because the effectiveness variable is unknown.

CEngage internal auditors to perform a review of the project to determine why and how the

Engaging internal auditors to review the project is a reactive escalation step that is premature before the security team has first assessed the technical alignment between control design and business requirements.

DReview to determine if control effectiveness is in line with the complexity of the solution.Correct

Before taking any corrective or escalation action, security professionals must first assess whether the implemented controls are achieving their intended security objectives proportionate to the operational burden they impose. Reviewing control effectiveness against solution complexity allows the organization to make an informed decision about whether the current design is appropriate, over-engineered, or needs tuning - this analysis must precede any SLA changes, cost-benefit work, or audit engagement.

Concept tested: Security control effectiveness review vs operational complexity

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#network segmentation#firewall management#control effectiveness#risk assessment

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice