nerdexam
CompTIA

CAS-002 · Question #65

Company XYZ is selling its manufacturing business consisting of one plant to a competitor, Company QRS. All of the people will become QRS employees, but will retain permissions to plant-specific…

The correct answer is B. Co-mingling of company networks. The HIGHEST risk to Company XYZ is the co-mingling of the two company networks. When Company QRS connects the plant to its own network, XYZ's network becomes interconnected with a competitor's network. This exposes XYZ's broader corporate systems, intellectual property, and…

Integration of Computing, Communications and Business Disciplines

Question

Company XYZ is selling its manufacturing business consisting of one plant to a competitor, Company QRS. All of the people will become QRS employees, but will retain permissions to plant-specific information and resources for one month. To ease the transition, Company QRS also connected the plant and employees to the Company QRS network. Which of the following threats is the HIGHEST risk to Company XYZ?

Options

  • AMalware originating from Company XYZ's network
  • BCo-mingling of company networks
  • CLack of an IPSec connection between the two networks
  • DLoss of proprietary plant information

How the community answered

(44 responses)
  • A
    16% (7)
  • B
    43% (19)
  • C
    9% (4)
  • D
    32% (14)

Explanation

The HIGHEST risk to Company XYZ is the co-mingling of the two company networks. When Company QRS connects the plant to its own network, XYZ's network becomes interconnected with a competitor's network. This exposes XYZ's broader corporate systems, intellectual property, and sensitive data - far beyond just the plant-specific information - to potential unauthorized access by QRS employees or any threat actors on QRS's network. Answer D (loss of proprietary plant information) is a risk, but it is a known, scoped risk that is being managed by granting only plant-specific permissions for one month. Co-mingling the networks is the broader, less controlled threat. Answer A (malware from XYZ) and Answer C (lack of IPSec) are secondary concerns compared to the fundamental network boundary violation.

Topics

#network co-mingling#M&A security#access control#data exfiltration

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice