CAS-003 · Question #651
A security administrator is opening connectivity on a firewall between Organization A and Organization B Organization B just acquired Organization A. Which of the following risk mitigation…
The correct answer is D. IPS/IDS monitoring on the new connection. When connecting two previously isolated networks - particularly in a post-acquisition scenario - the security posture, patch levels, and threat exposure of the newly connected organization are unknown. Deploying IPS/IDS monitoring on the new connection provides real-time…
Question
A security administrator is opening connectivity on a firewall between Organization A and Organization B Organization B just acquired Organization A. Which of the following risk mitigation strategies should the administrator implement to reduce the risk involved with this change?
Options
- ADLP on internal network nodes
- BA network traffic analyzer for incoming traffic
- CA proxy server to examine outgoing web traffic
- DIPS/IDS monitoring on the new connection
How the community answered
(63 responses)- A8% (5)
- B5% (3)
- C14% (9)
- D73% (46)
Explanation
When connecting two previously isolated networks - particularly in a post-acquisition scenario - the security posture, patch levels, and threat exposure of the newly connected organization are unknown. Deploying IPS/IDS monitoring on the new connection provides real-time detection of malicious traffic, lateral movement attempts, malware propagation, and anomalous behavior crossing the link. This gives visibility into threats before they spread deeper into either network. DLP (A) addresses data exfiltration but not active attack traffic. A network traffic analyzer (B) provides visibility but lacks active blocking capability. A proxy server (C) only covers web traffic, leaving other protocols unmonitored. IPS/IDS is the most comprehensive risk mitigation for a newly opened network interconnect.
Topics
Community Discussion
No community discussion yet for this question.