CAS-002 · Question #702
A large enterprise is expanding through the acquisition of a second corporation. Which of the following should be undertaken FIRST before connecting the networks of the newly formed entity?
The correct answer is C. Develop a risk analysis for the merged networks. Before connecting two merged corporate networks, a risk analysis must be performed first so that threats are understood and mitigation decisions are properly informed.
Question
A large enterprise is expanding through the acquisition of a second corporation. Which of the following should be undertaken FIRST before connecting the networks of the newly formed entity?
Options
- AA system and network scan to determine if all of the systems are secure.
- BImplement a firewall/DMZ system between the networks.
- CDevelop a risk analysis for the merged networks.
- DConduct a complete review of the security posture of the acquired corporation.
How the community answered
(36 responses)- A17% (6)
- B6% (2)
- C75% (27)
- D3% (1)
Why each option
Before connecting two merged corporate networks, a risk analysis must be performed first so that threats are understood and mitigation decisions are properly informed.
Scanning systems to verify they are secure is a technical activity that should occur after risks have been identified and prioritized, not before the risk landscape is understood.
Implementing a firewall or DMZ is a mitigation control and should be designed based on the results of a risk analysis rather than deployed without that context.
Developing a risk analysis first establishes a clear understanding of the threats, vulnerabilities, and potential impacts introduced by merging the two network environments. Without this foundational step, any subsequent actions - such as scanning systems or deploying firewalls - lack prioritization and may address the wrong risks. Risk analysis drives all downstream security decisions during a merger or acquisition and is the recognized first step in secure network integration.
Reviewing the acquired corporation's security posture is an important input into the risk analysis but is a narrower sub-task that feeds into, rather than replaces, the full risk analysis process.
Concept tested: Risk analysis as first step in network merger
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.