CAS-002 · Question #750
An insurance company is looking to purchase a smaller company in another country. Which of the following tasks would the security administrator perform as part of the security due diligence?
The correct answer is B. Review the security policies and standards. Security due diligence in mergers and acquisitions focuses on assessing the overall security governance and risk posture of the target company, not performing active technical assessments. Reviewing security policies and standards is the most strategic and appropriate activity.
Question
An insurance company is looking to purchase a smaller company in another country. Which of the following tasks would the security administrator perform as part of the security due diligence?
Options
- AReview switch and router configurations
- BReview the security policies and standards
- CPerform a network penetration test
- DReview the firewall rule set and IPS logs
How the community answered
(23 responses)- B87% (20)
- C9% (2)
- D4% (1)
Why each option
Security due diligence in mergers and acquisitions focuses on assessing the overall security governance and risk posture of the target company, not performing active technical assessments. Reviewing security policies and standards is the most strategic and appropriate activity.
Reviewing individual switch and router configurations is a granular, operational-level activity that does not provide the governance overview and risk assessment required for acquisition due diligence.
Security policies and standards reflect the target company's security governance maturity, regulatory compliance posture, risk management practices, and overall program effectiveness - the primary concerns when evaluating inherited risk in an acquisition. This review identifies systemic liabilities, compliance gaps, and risk exposure that the acquiring company would assume without requiring intrusive or disruptive access to the target's infrastructure. It provides the broadest and most strategically relevant security risk assessment appropriate to an international acquisition context.
A penetration test is an active, intrusive engagement requiring explicit written authorization, legal agreements, and significant coordination - it is not a standard or appropriate component of initial security due diligence in an M&A context.
Reviewing firewall rule sets and IPS logs is a narrow technical activity focused on specific operational controls rather than the broad security posture and policy framework that due diligence requires.
Concept tested: Security due diligence in mergers and acquisitions
Topics
Community Discussion
No community discussion yet for this question.