CAS-003 · Question #218
Which of the following BEST represents a risk associated with merging two enterprises during an acquisition?
The correct answer is C. Merging two enterprise networks could result in an expanded attack surface and could cause. Merging two enterprise networks during an acquisition increases the attack surface by combining previously separate security perimeters with differing configurations. This expanded surface raises the likelihood that attackers can find and exploit gaps during the integration…
Question
Which of the following BEST represents a risk associated with merging two enterprises during an acquisition?
Options
- AThe consolidation of two different IT enterprises increases the likelihood of the data loss because
- BIntegrating two different IT systems might result in a successful data breach if threat intelligence
- CMerging two enterprise networks could result in an expanded attack surface and could cause
- DExpanding the set of data owners requires an in-depth review of all data classification decisions,
How the community answered
(43 responses)- A12% (5)
- B5% (2)
- C81% (35)
- D2% (1)
Why each option
Merging two enterprise networks during an acquisition increases the attack surface by combining previously separate security perimeters with differing configurations. This expanded surface raises the likelihood that attackers can find and exploit gaps during the integration period.
IT consolidation does not inherently increase the likelihood of data loss - the primary risk introduced is an expanded attack surface from combining security boundaries, not data management failure.
The success of a data breach depends on vulnerabilities and attacker capability, not on whether threat intelligence is shared between integrated systems.
When two enterprise networks are merged, the resulting environment exposes a larger combined perimeter with heterogeneous security controls, unresolved trust relationships, and potential policy mismatches that create new lateral movement paths. The transitional state before a unified security posture is fully established is particularly vulnerable because legacy access permissions and inconsistent configurations from both organizations coexist.
Reviewing data classification after an acquisition is a compliance and governance task - it is a mitigation activity, not a risk introduced by the merger itself.
Concept tested: Enterprise acquisition cybersecurity risk - expanded attack surface
Source: https://www.nist.gov/cyberframework
Topics
Community Discussion
No community discussion yet for this question.