nerdexam
CompTIA

CAS-002 · Question #606

Company A is purchasing Company B, and will import all of Company B's users into its authentication system. Company A uses 802.1x with a RADIUS server, while Company B uses a captive SSL portal with…

The correct answer is D. Enable 802.1x on Company B's network devices. When one company acquires another, the acquired company's infrastructure should be migrated to align with the acquiring company's authentication standard to maintain a single, unified security architecture.

Technical Integration of Enterprise Components

Question

Company A is purchasing Company B, and will import all of Company B's users into its authentication system. Company A uses 802.1x with a RADIUS server, while Company B uses a captive SSL portal with an LDAP backend. Which of the following is the BEST way to integrate these two networks?

Options

  • AEnable RADIUS and end point security on Company B's network devices.
  • BEnable LDAP authentication on Company A's network devices.
  • CEnable LDAP/TLS authentication on Company A's network devices.
  • DEnable 802.1x on Company B's network devices.

How the community answered

(38 responses)
  • A
    13% (5)
  • B
    8% (3)
  • C
    3% (1)
  • D
    76% (29)

Why each option

When one company acquires another, the acquired company's infrastructure should be migrated to align with the acquiring company's authentication standard to maintain a single, unified security architecture.

AEnable RADIUS and end point security on Company B's network devices.

Simply enabling RADIUS and endpoint security on Company B's devices does not integrate them into Company A's 802.1x authentication framework - it does not migrate B's devices to use A's RADIUS server as the authenticator.

BEnable LDAP authentication on Company A's network devices.

Enabling plain LDAP authentication on Company A's devices would require A to downgrade or alter its infrastructure to match B's older portal-based system, which is the wrong direction for an acquisition integration.

CEnable LDAP/TLS authentication on Company A's network devices.

Enabling LDAP/TLS on Company A's devices is a marginally more secure variant of option B but still incorrectly shifts Company A's infrastructure to match Company B's model rather than the reverse.

DEnable 802.1x on Company B's network devices.Correct

Company A is the acquiring entity and its 802.1x/RADIUS infrastructure is the target authentication system. Enabling 802.1x on Company B's network devices brings B's network into compliance with A's existing standard, allowing B's users - once imported into A's RADIUS backend - to authenticate seamlessly using the same protocol. This avoids fragmenting authentication systems and leverages A's already-established infrastructure as the authoritative system.

Concept tested: 802.1x and RADIUS network authentication integration during acquisition

Source: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-top

Topics

#802.1x#RADIUS#LDAP#network authentication integration

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice