CAS-003 · Question #204
Company XYZ has just purchased Company ABC through a new acquisition. A business decision has been made to integrate the two company's networks, application, and several basic services. The initial…
The correct answer is A. Place a Company ABC managed firewall in Company XYZ's hub site; then place Company. The requirements state that Company XYZ is 'partially trusted,' needs access to specific Company ABC resources, and must not experience performance degradation. Placing a Company ABC-managed firewall at Company XYZ's hub site satisfies all three constraints: it enforces…
Question
Company XYZ has just purchased Company ABC through a new acquisition. A business decision has been made to integrate the two company's networks, application, and several basic services. The initial integration of the two companies has specified the following requirements:
- Company XYZ requires access to the web intranet, file, print, secure
FTP server, and authentication domain resources
- Company XYZ is being on boarded into
- Company ABC's authentication domain Company XYZ is considered
partially trusted
- Company XYZ does not want performance issues when accessing ABC's
systems Which of the following network security solutions will BEST meet the above requirements?
Options
- APlace a Company ABC managed firewall in Company XYZ's hub site; then place Company
- BRequire Company XYZ to manage the router ACLs, controlling access to Company ABC
- CPlace no restrictions on internal network connectivity between Company XYZ and Company
- DPlace file, print, secure FTP server and authentication domain servers at Company XYZ's
How the community answered
(43 responses)- A67% (29)
- B5% (2)
- C9% (4)
- D19% (8)
Explanation
The requirements state that Company XYZ is 'partially trusted,' needs access to specific Company ABC resources, and must not experience performance degradation. Placing a Company ABC-managed firewall at Company XYZ's hub site satisfies all three constraints: it enforces granular access control to only the permitted ABC resources (web intranet, file, print, SFTP, authentication domain), it keeps management of the firewall under ABC's control (maintaining the trust boundary), and it places the enforcement point close to XYZ users to minimize latency. Option B gives XYZ control over ACLs protecting ABC's systems, which is inappropriate for a partially trusted partner. Option C removes all restrictions, violating the partial-trust model. Option D moves ABC's servers to XYZ's location, which creates significant security and management problems without addressing the controlled access requirement.
Topics
Community Discussion
No community discussion yet for this question.