nerdexam
CompTIA

CAS-002 · Question #750

An insurance company is looking to purchase a smaller company in another country. Which of the following tasks would the security administrator perform as part of the security due diligence?

The correct answer is B. Review the security policies and standards. Security due diligence in mergers and acquisitions focuses on assessing the overall security governance and risk posture of the target company, not performing active technical assessments. Reviewing security policies and standards is the most strategic and appropriate activity.

Research and Analysis

Question

An insurance company is looking to purchase a smaller company in another country. Which of the following tasks would the security administrator perform as part of the security due diligence?

Options

  • AReview switch and router configurations
  • BReview the security policies and standards
  • CPerform a network penetration test
  • DReview the firewall rule set and IPS logs

How the community answered

(23 responses)
  • B
    87% (20)
  • C
    9% (2)
  • D
    4% (1)

Why each option

Security due diligence in mergers and acquisitions focuses on assessing the overall security governance and risk posture of the target company, not performing active technical assessments. Reviewing security policies and standards is the most strategic and appropriate activity.

AReview switch and router configurations

Reviewing individual switch and router configurations is a granular, operational-level activity that does not provide the governance overview and risk assessment required for acquisition due diligence.

BReview the security policies and standardsCorrect

Security policies and standards reflect the target company's security governance maturity, regulatory compliance posture, risk management practices, and overall program effectiveness - the primary concerns when evaluating inherited risk in an acquisition. This review identifies systemic liabilities, compliance gaps, and risk exposure that the acquiring company would assume without requiring intrusive or disruptive access to the target's infrastructure. It provides the broadest and most strategically relevant security risk assessment appropriate to an international acquisition context.

CPerform a network penetration test

A penetration test is an active, intrusive engagement requiring explicit written authorization, legal agreements, and significant coordination - it is not a standard or appropriate component of initial security due diligence in an M&A context.

DReview the firewall rule set and IPS logs

Reviewing firewall rule sets and IPS logs is a narrow technical activity focused on specific operational controls rather than the broad security posture and policy framework that due diligence requires.

Concept tested: Security due diligence in mergers and acquisitions

Topics

#security due diligence#M&A security#policy review#risk assessment

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice