nerdexam
CompTIA

CAS-002 · Question #716

When Company A and Company B merged, the network security administrator for Company A was tasked with joining the two networks. Which of the following should be done FIRST?

The correct answer is C. Perform a vulnerability assessment on Company B's network. Before connecting two merged company networks, a vulnerability assessment of the unfamiliar network must be performed first to identify existing weaknesses and avoid importing unknown risks into the combined environment.

Research and Analysis

Question

When Company A and Company B merged, the network security administrator for Company A was tasked with joining the two networks. Which of the following should be done FIRST?

Options

  • AImplement a unified IPv6 addressing scheme on the entire network.
  • BConduct a penetration test of Company B's network.
  • CPerform a vulnerability assessment on Company B's network.
  • DPerform a peer code review on Company B's application.

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    88% (37)
  • D
    7% (3)

Why each option

Before connecting two merged company networks, a vulnerability assessment of the unfamiliar network must be performed first to identify existing weaknesses and avoid importing unknown risks into the combined environment.

AImplement a unified IPv6 addressing scheme on the entire network.

Implementing a unified IPv6 addressing scheme is an infrastructure reconfiguration task that should only happen after the security posture of both networks has been assessed and any risks mitigated.

BConduct a penetration test of Company B's network.

Penetration testing is an active, adversarial assessment technique that is typically scoped and executed after a vulnerability assessment has already mapped the attack surface to prioritize.

CPerform a vulnerability assessment on Company B's network.Correct

A vulnerability assessment is a passive, non-destructive evaluation that catalogs known misconfigurations, unpatched software, and policy gaps on Company B's network before any integration takes place. Running it first prevents the administrator from inadvertently bridging Company A's network to an already-compromised or weakly secured environment. The assessment results also serve as the security baseline required to plan all subsequent integration and remediation steps safely.

DPerform a peer code review on Company B's application.

A peer code review evaluates the correctness and security of application source code, which is unrelated to the immediate task of safely integrating two network infrastructures.

Concept tested: Vulnerability assessment as prerequisite to network integration

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#vulnerability assessment#network merger#security due diligence#acquisition security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice