nerdexam
CompTIA

CAS-002 · Question #702

A large enterprise is expanding through the acquisition of a second corporation. Which of the following should be undertaken FIRST before connecting the networks of the newly formed entity?

The correct answer is C. Develop a risk analysis for the merged networks. Before connecting two merged corporate networks, a risk analysis must be performed first so that threats are understood and mitigation decisions are properly informed.

Research and Analysis

Question

A large enterprise is expanding through the acquisition of a second corporation. Which of the following should be undertaken FIRST before connecting the networks of the newly formed entity?

Options

  • AA system and network scan to determine if all of the systems are secure.
  • BImplement a firewall/DMZ system between the networks.
  • CDevelop a risk analysis for the merged networks.
  • DConduct a complete review of the security posture of the acquired corporation.

How the community answered

(36 responses)
  • A
    17% (6)
  • B
    6% (2)
  • C
    75% (27)
  • D
    3% (1)

Why each option

Before connecting two merged corporate networks, a risk analysis must be performed first so that threats are understood and mitigation decisions are properly informed.

AA system and network scan to determine if all of the systems are secure.

Scanning systems to verify they are secure is a technical activity that should occur after risks have been identified and prioritized, not before the risk landscape is understood.

BImplement a firewall/DMZ system between the networks.

Implementing a firewall or DMZ is a mitigation control and should be designed based on the results of a risk analysis rather than deployed without that context.

CDevelop a risk analysis for the merged networks.Correct

Developing a risk analysis first establishes a clear understanding of the threats, vulnerabilities, and potential impacts introduced by merging the two network environments. Without this foundational step, any subsequent actions - such as scanning systems or deploying firewalls - lack prioritization and may address the wrong risks. Risk analysis drives all downstream security decisions during a merger or acquisition and is the recognized first step in secure network integration.

DConduct a complete review of the security posture of the acquired corporation.

Reviewing the acquired corporation's security posture is an important input into the risk analysis but is a narrower sub-task that feeds into, rather than replaces, the full risk analysis process.

Concept tested: Risk analysis as first step in network merger

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk analysis#network merger#M&A security#due diligence

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice