CAS-002 · Question #714
A new vendor product has been acquired to replace a legacy perimeter security product. There are significant time constraints due to the existing solution nearing end-of-life with no options for…
The correct answer is D. Test the new solution, migrate to the new solution, and decommission the old solution. When replacing a legacy security product under time constraints, the correct sequence is to test the new solution first, migrate traffic to it, then decommission the old one to maintain continuous coverage.
Question
A new vendor product has been acquired to replace a legacy perimeter security product. There are significant time constraints due to the existing solution nearing end-of-life with no options for extended support. It has been emphasized that only essential activities be performed. Which of the following sequences BEST describes the order of activities when balancing security posture and time constraints?
Options
- AInstall the new solution, migrate to the new solution, and test the new solution.
- BPurchase the new solution, test the new solution, and migrate to the new solution.
- CDecommission the old solution, install the new solution, and test the new solution.
- DTest the new solution, migrate to the new solution, and decommission the old solution.
How the community answered
(26 responses)- A4% (1)
- B15% (4)
- C8% (2)
- D73% (19)
Why each option
When replacing a legacy security product under time constraints, the correct sequence is to test the new solution first, migrate traffic to it, then decommission the old one to maintain continuous coverage.
Installing and migrating before testing risks moving production traffic onto an unvalidated solution, which could silently fail to enforce security policy and leave the perimeter exposed.
Listing 'purchase' conflates a procurement step with a deployment activity, and this sequence omits any controlled decommissioning of the old solution after the migration is verified.
Decommissioning the old solution before the new one has been tested or migration has occurred creates a window with no perimeter protection, directly undermining the security posture requirement.
Testing the new solution before migration validates that it functions correctly and will not leave a gap in perimeter protection when traffic is cut over. Migrating only after a successful test confirms operational readiness, and decommissioning last ensures the legacy product continues to protect the perimeter until the replacement is confirmed working. This three-step sequence covers only the essential activities while preserving security posture throughout the transition.
Concept tested: Secure technology replacement and migration sequencing
Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final
Topics
Community Discussion
No community discussion yet for this question.