CAS-002 · Question #619
The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The CEO argues that…
The correct answer is B. The aggregation of employees on a corporate network makes it a more valuable target for. Corporate networks concentrate many high-value assets in one location, making perimeter defense far more critical than protecting any single home network.
Question
The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The CEO argues that the company cannot protect its employees at home, so the risk at work is no different. Which of the following BEST explains why this company should proceed with protecting its corporate network boundary?
Options
- AThe corporate network is the only network that is audited by regulators and customers.
- BThe aggregation of employees on a corporate network makes it a more valuable target for
- CHome networks are unknown to attackers and less likely to be targeted directly.
- DEmployees are more likely to be using personal computers for general web browsing when
How the community answered
(25 responses)- A4% (1)
- B80% (20)
- C4% (1)
- D12% (3)
Why each option
Corporate networks concentrate many high-value assets in one location, making perimeter defense far more critical than protecting any single home network.
Regulatory audits and customer reviews are compliance-driven concerns, not a technical security rationale for protecting the network from adversarial threats.
The aggregation of all employees, their credentials, and sensitive corporate data onto a single network creates a high-value target that is disproportionately attractive to attackers compared to individual home setups. A single successful breach of the corporate perimeter can yield access to all users and systems simultaneously, a payoff that no individual home network can match. This aggregation risk is the core justification for investing in perimeter hardening even when some employees work remotely.
Home networks are not unknown to attackers - they are routinely targeted through phishing, compromised consumer routers, and ISP-level vulnerabilities, making this claim technically inaccurate.
Personal web browsing habits on home computers represent a separate endpoint risk and do not provide a technical justification for why the corporate network boundary specifically needs hardening.
Concept tested: Aggregation risk justifying corporate perimeter defense
Source: https://csrc.nist.gov/publications/detail/sp/800-41/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.