CAS-002 · Question #99
An existing enterprise architecture included an enclave where sensitive research and development work was conducted. This network enclave also served as a storage location for proprietary corporate…
The correct answer is A. Emerging business requirements led to the de-perimiterization of the network. Over time, researchers bypassed the original firewall perimeter by connecting directly to external resources and adding wireless devices, a process known as de-perimeterization.
Question
An existing enterprise architecture included an enclave where sensitive research and development work was conducted. This network enclave also served as a storage location for proprietary corporate data and records. The initial security architect chose to protect the enclave by restricting access to a single physical port on a firewall. All downstream network devices were isolated from the rest of the network and communicated solely through the single 100mbps firewall port. Over time, researchers connected devices on the protected enclave directly to external resources and corporate data stores. Mobile and wireless devices were also added to the enclave to support high speed data research. Which of the following BEST describes the process which weakened the security posture of the enclave?
Options
- AEmerging business requirements led to the de-perimiterization of the network.
- BEmerging security threats rendered the existing architecture obsolete.
- CThe single firewall port was oversaturated with network packets.
- DThe shrinking of an overall attack surface due to the additional access.
How the community answered
(31 responses)- A58% (18)
- B3% (1)
- C26% (8)
- D13% (4)
Why each option
Over time, researchers bypassed the original firewall perimeter by connecting directly to external resources and adding wireless devices, a process known as de-perimeterization.
De-perimeterization occurs when the defined boundary separating a protected network from untrusted networks erodes through incremental changes. Researchers connecting devices directly to external resources and adding mobile/wireless endpoints removed the single-point firewall protection, dissolving the enclave's security boundary without any formal architectural decision.
No new external threats are described; the weakening resulted from internal architectural drift, not from threat evolution rendering controls obsolete.
Port saturation would cause performance degradation and dropped packets, not a loss of access controls or a weakened security posture.
The attack surface grew rather than shrank because new uncontrolled access points were added, increasing exposure to external threats.
Concept tested: Network de-perimeterization and enclave security erosion
Source: https://csrc.nist.gov/publications/detail/sp/800-41/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.