nerdexam
CompTIA

CAS-002 · Question #619

The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The CEO argues that…

The correct answer is B. The aggregation of employees on a corporate network makes it a more valuable target for. Corporate networks concentrate many high-value assets in one location, making perimeter defense far more critical than protecting any single home network.

Enterprise Security

Question

The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The CEO argues that the company cannot protect its employees at home, so the risk at work is no different. Which of the following BEST explains why this company should proceed with protecting its corporate network boundary?

Options

  • AThe corporate network is the only network that is audited by regulators and customers.
  • BThe aggregation of employees on a corporate network makes it a more valuable target for
  • CHome networks are unknown to attackers and less likely to be targeted directly.
  • DEmployees are more likely to be using personal computers for general web browsing when

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    80% (20)
  • C
    4% (1)
  • D
    12% (3)

Why each option

Corporate networks concentrate many high-value assets in one location, making perimeter defense far more critical than protecting any single home network.

AThe corporate network is the only network that is audited by regulators and customers.

Regulatory audits and customer reviews are compliance-driven concerns, not a technical security rationale for protecting the network from adversarial threats.

BThe aggregation of employees on a corporate network makes it a more valuable target forCorrect

The aggregation of all employees, their credentials, and sensitive corporate data onto a single network creates a high-value target that is disproportionately attractive to attackers compared to individual home setups. A single successful breach of the corporate perimeter can yield access to all users and systems simultaneously, a payoff that no individual home network can match. This aggregation risk is the core justification for investing in perimeter hardening even when some employees work remotely.

CHome networks are unknown to attackers and less likely to be targeted directly.

Home networks are not unknown to attackers - they are routinely targeted through phishing, compromised consumer routers, and ISP-level vulnerabilities, making this claim technically inaccurate.

DEmployees are more likely to be using personal computers for general web browsing when

Personal web browsing habits on home computers represent a separate endpoint risk and do not provide a technical justification for why the corporate network boundary specifically needs hardening.

Concept tested: Aggregation risk justifying corporate perimeter defense

Source: https://csrc.nist.gov/publications/detail/sp/800-41/rev-1/final

Topics

#network perimeter security#risk aggregation#telecommuting#target value

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice