nerdexam
CompTIA

CAS-002 · Question #789

A company has decided to change its current business direction and refocus on core business. Consequently, several company sub-businesses are in the process of being sold-off. A security consultant…

The correct answer is D. Identify the current state from a security viewpoint. Based on the demerger, assess what the. When advising on a de-merger, a security consultant must first establish a baseline of the current security state and then assess how the separation changes that posture for each resulting entity.

Integration of Computing, Communications and Business Disciplines

Question

A company has decided to change its current business direction and refocus on core business. Consequently, several company sub-businesses are in the process of being sold-off. A security consultant has been engaged to advise on residual information security concerns with a de- merger. From a high-level perspective, which of the following BEST provides the procedure that the consultant should follow?

Options

  • APerform a penetration test for the current state of the company. Perform another penetration test
  • BDuplicate security-based assets should be sold off for commercial gain to ensure that the security
  • CExplain that security consultants are not trained to offer advice on company acquisitions or
  • DIdentify the current state from a security viewpoint. Based on the demerger, assess what the

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    9% (4)
  • C
    16% (7)
  • D
    70% (30)

Why each option

When advising on a de-merger, a security consultant must first establish a baseline of the current security state and then assess how the separation changes that posture for each resulting entity.

APerform a penetration test for the current state of the company. Perform another penetration test

Penetration testing is a tactical point-in-time activity that tests exploitability; it does not provide the strategic, high-level risk assessment or transition planning that a de-merger requires.

BDuplicate security-based assets should be sold off for commercial gain to ensure that the security

Selling security assets for commercial gain is not a recognized information security practice and could increase exposure by transferring controls outside the organization without proper due diligence.

CExplain that security consultants are not trained to offer advice on company acquisitions or

Security consultants are specifically trained to assess information security risks during mergers, acquisitions, and de-mergers, making this answer factually incorrect and an abdication of professional responsibility.

DIdentify the current state from a security viewpoint. Based on the demerger, assess what theCorrect

Effective security consulting for a de-merger follows a risk assessment methodology: document the current security posture (assets, controls, data flows, shared services), then model the post-demerger state for each separated entity to identify gaps, residual risks, and remediation requirements. This ensures neither resulting organization is left with unaddressed vulnerabilities or shared credentials and systems.

Concept tested: Security risk assessment methodology for organizational de-mergers

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#de-merger security#security governance#risk assessment#security consulting

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice