CAS-002 · Question #260
Company XYZ has just purchased Company ABC through a new acquisition. A business decision has been made to integrate the two company's networks, application, and several basic services. The initial…
The correct answer is A. Place a Company ABC managed firewall in Company XYZ's hub site; then place Company. Placing an ABC-managed firewall at XYZ's hub site enforces the partial-trust boundary while keeping access latency low for XYZ users connecting to ABC resources.
Question
Company XYZ has just purchased Company ABC through a new acquisition. A business decision has been made to integrate the two company's networks, application, and several basic services. The initial integration of the two companies has specified the following requirements:
- Company XYZ requires access to the web intranet, file, print, secure
FTP server, and authentication domain resources
- Company XYZ is being on boarded into
- Company ABC's authentication domain Company XYZ is considered
partially trusted
- Company XYZ does not want performance issues when accessing ABC's
systems Which of the following network security solutions will BEST meet the above requirements?
Options
- APlace a Company ABC managed firewall in Company XYZ's hub site; then place Company
- BRequire Company XYZ to manage the router ACLs, controlling access to Company ABC
- CPlace no restrictions on internal network connectivity between Company XYZ and Company
- DPlace file, print, secure FTP server and authentication domain servers at Company XYZ's
How the community answered
(30 responses)- A63% (19)
- B23% (7)
- C3% (1)
- D10% (3)
Why each option
Placing an ABC-managed firewall at XYZ's hub site enforces the partial-trust boundary while keeping access latency low for XYZ users connecting to ABC resources.
Having Company ABC manage the firewall placed at Company XYZ's hub site ensures that access to ABC's internal resources - including the web intranet, file, print, SFTP servers, and authentication domain - is controlled by the trusted party rather than the partially trusted XYZ. Positioning the firewall at XYZ's hub site minimizes round-trip latency for XYZ users, addressing the performance requirement. This architecture satisfies both the partial-trust constraint and the onboarding of XYZ into ABC's authentication domain.
Allowing XYZ to manage the router ACLs controlling access to ABC's systems contradicts the partial-trust designation, as a partially trusted party should not control its own access permissions to the trusted party's resources.
Placing no restrictions on internal connectivity ignores the partial-trust requirement entirely and establishes no security boundary between the two companies' networks.
Placing servers at XYZ's hub site without ABC-managed access controls does not address the authentication and trust requirements and introduces risk by moving sensitive ABC resources into a less trusted environment.
Concept tested: Network security architecture for partially trusted partner integration
Topics
Community Discussion
No community discussion yet for this question.