nerdexam
CompTIA

CAS-002 · Question #260

Company XYZ has just purchased Company ABC through a new acquisition. A business decision has been made to integrate the two company's networks, application, and several basic services. The initial…

The correct answer is A. Place a Company ABC managed firewall in Company XYZ's hub site; then place Company. Placing an ABC-managed firewall at XYZ's hub site enforces the partial-trust boundary while keeping access latency low for XYZ users connecting to ABC resources.

Technical Integration of Enterprise Components

Question

Company XYZ has just purchased Company ABC through a new acquisition. A business decision has been made to integrate the two company's networks, application, and several basic services. The initial integration of the two companies has specified the following requirements:

  • Company XYZ requires access to the web intranet, file, print, secure

FTP server, and authentication domain resources

  • Company XYZ is being on boarded into
  • Company ABC's authentication domain Company XYZ is considered

partially trusted

  • Company XYZ does not want performance issues when accessing ABC's

systems Which of the following network security solutions will BEST meet the above requirements?

Options

  • APlace a Company ABC managed firewall in Company XYZ's hub site; then place Company
  • BRequire Company XYZ to manage the router ACLs, controlling access to Company ABC
  • CPlace no restrictions on internal network connectivity between Company XYZ and Company
  • DPlace file, print, secure FTP server and authentication domain servers at Company XYZ's

How the community answered

(30 responses)
  • A
    63% (19)
  • B
    23% (7)
  • C
    3% (1)
  • D
    10% (3)

Why each option

Placing an ABC-managed firewall at XYZ's hub site enforces the partial-trust boundary while keeping access latency low for XYZ users connecting to ABC resources.

APlace a Company ABC managed firewall in Company XYZ's hub site; then place CompanyCorrect

Having Company ABC manage the firewall placed at Company XYZ's hub site ensures that access to ABC's internal resources - including the web intranet, file, print, SFTP servers, and authentication domain - is controlled by the trusted party rather than the partially trusted XYZ. Positioning the firewall at XYZ's hub site minimizes round-trip latency for XYZ users, addressing the performance requirement. This architecture satisfies both the partial-trust constraint and the onboarding of XYZ into ABC's authentication domain.

BRequire Company XYZ to manage the router ACLs, controlling access to Company ABC

Allowing XYZ to manage the router ACLs controlling access to ABC's systems contradicts the partial-trust designation, as a partially trusted party should not control its own access permissions to the trusted party's resources.

CPlace no restrictions on internal network connectivity between Company XYZ and Company

Placing no restrictions on internal connectivity ignores the partial-trust requirement entirely and establishes no security boundary between the two companies' networks.

DPlace file, print, secure FTP server and authentication domain servers at Company XYZ's

Placing servers at XYZ's hub site without ABC-managed access controls does not address the authentication and trust requirements and introduces risk by moving sensitive ABC resources into a less trusted environment.

Concept tested: Network security architecture for partially trusted partner integration

Topics

#network integration#firewall placement#trust boundaries#acquisition

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice