CAS-002 · Question #794
A large company is preparing to merge with a smaller company. The smaller company has been very profitable, but the smaller company's main applications were created in-house. Which of the following…
The correct answer is C. A security assessment should be performed to establish the risks of integration or co-existence. Pre-merger due diligence requires a security assessment to identify integration risks before exposing the acquiring company to vulnerabilities in the smaller company's custom applications.
Question
A large company is preparing to merge with a smaller company. The smaller company has been very profitable, but the smaller company's main applications were created in-house. Which of the following actions should the large company's security administrator take in preparation for the merger?
Options
- AA review of the mitigations implemented from the most recent audit findings of the smaller
- BAn ROI calculation should be performed to determine which company's application should be
- CA security assessment should be performed to establish the risks of integration or co-existence.
- DA regression test should be performed on the in-house software to determine security risks
How the community answered
(41 responses)- A12% (5)
- B2% (1)
- C80% (33)
- D5% (2)
Why each option
Pre-merger due diligence requires a security assessment to identify integration risks before exposing the acquiring company to vulnerabilities in the smaller company's custom applications.
Reviewing prior audit mitigations provides historical context but does not proactively identify new integration risks created by combining two distinct environments.
An ROI calculation is a business finance decision, not a security action, and does not address the security risks of integrating unfamiliar in-house applications.
A security assessment establishes the risk posture of the smaller company's in-house applications and identifies vulnerabilities, dependencies, and integration risks before the merger is finalized. This proactive step allows the security team to make informed decisions about integration strategy, co-existence, or remediation requirements before new attack surfaces are introduced into the combined environment.
Regression testing validates that existing functionality still works after code changes; it does not comprehensively assess the security risks of integration or co-existence with another company's systems.
Concept tested: Security assessment for merger and acquisition due diligence
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.