nerdexam
CompTIA

CAS-002 · Question #804

Joe is a security architect who is tasked with choosing a new NIPS platform that has the ability to perform SSL inspection, analyze up to 10Gbps of traffic, can be centrally managed and only reveals…

The correct answer is A. Research new technology vendors to look for potential products. Contribute to an RFP and then. Proper procurement of a NIPS platform requires a structured vendor research and RFP process to ensure all technical and operational requirements are met before selection.

Research and Analysis

Question

Joe is a security architect who is tasked with choosing a new NIPS platform that has the ability to perform SSL inspection, analyze up to 10Gbps of traffic, can be centrally managed and only reveals inspected application payload data to specified internal security employees. Which of the following steps should Joe take to reach the desired outcome?

Options

  • AResearch new technology vendors to look for potential products. Contribute to an RFP and then
  • BEvaluate relevant RFC and ISO standards to choose an appropriate vendor product. Research
  • CConsider outsourcing the product evaluation and ongoing management to an outsourced provider
  • DChoose a popular NIPS product and then consider outsourcing the ongoing device management
  • EEnsure that the NIPS platform can also deal with recent technological advancements, such as

How the community answered

(33 responses)
  • A
    82% (27)
  • B
    6% (2)
  • C
    3% (1)
  • D
    9% (3)

Why each option

Proper procurement of a NIPS platform requires a structured vendor research and RFP process to ensure all technical and operational requirements are met before selection.

AResearch new technology vendors to look for potential products. Contribute to an RFP and thenCorrect

Researching vendors and contributing to a formal Request for Proposal (RFP) process is the correct approach because it ensures that all stated requirements - SSL inspection, 10Gbps throughput, centralized management, and role-based data visibility - are formally documented and evaluated against vendor offerings. An RFP process forces vendors to demonstrate compliance with specific requirements and allows for objective comparison, leading to an informed and defensible procurement decision.

BEvaluate relevant RFC and ISO standards to choose an appropriate vendor product. Research

RFC and ISO standards define protocols and frameworks but do not serve as vendor product selection criteria - using them as the primary evaluation basis would not directly identify which commercial NIPS products meet the specific technical requirements stated.

CConsider outsourcing the product evaluation and ongoing management to an outsourced provider

Outsourcing the evaluation and management to a third party does not address the specific requirement that only internal security employees should have access to inspected application payload data, creating a potential data confidentiality conflict.

DChoose a popular NIPS product and then consider outsourcing the ongoing device management

Selecting a product based on popularity rather than validated requirements is not a sound procurement practice and may result in a product that fails to meet critical technical specifications such as throughput or role-based payload visibility.

EEnsure that the NIPS platform can also deal with recent technological advancements, such as

Ensuring the platform handles recent technological advancements is a secondary consideration that should be part of the RFP requirements, not the primary step in the procurement process.

Concept tested: Security product procurement and RFP process

Source: https://www.nist.gov/system/files/documents/2017/05/09/nist_security_products_acquisition_guide.pdf

Topics

#NIPS#SSL inspection#vendor evaluation#RFP process

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice