nerdexam
CompTIA

CAS-003 · Question #895

While standing a proof-of-concept solution with a vendor, the following direction was given of connections to the default environments. Which of the following is using used to secure the three…

The correct answer is A. Separation of environments policy. When development, test, and production environments share the same DMZ, a formal separation of environments policy defines the administrative boundaries and procedures that prevent unintended cross-environment interaction.

Enterprise Security Architecture

Question

While standing a proof-of-concept solution with a vendor, the following direction was given of connections to the default environments. Which of the following is using used to secure the three environments from overlap if all of them reside on separate serves in the same DM2?

Options

  • ASeparation of environments policy
  • BLogical access controls
  • CSegmentation of VlLNs
  • DSubnetting of cloud environments

How the community answered

(40 responses)
  • A
    90% (36)
  • B
    3% (1)
  • C
    3% (1)
  • D
    5% (2)

Why each option

When development, test, and production environments share the same DMZ, a formal separation of environments policy defines the administrative boundaries and procedures that prevent unintended cross-environment interaction.

ASeparation of environments policyCorrect

A separation of environments policy establishes the rules, procedures, and governance controls that ensure development, test, and production systems remain distinct - this is the primary compensating control when all environments share a common network zone (the DMZ) and technical isolation alone does not fully address overlap risk.

BLogical access controls

Logical access controls restrict which users can authenticate to each environment but do not prevent the environments themselves from overlapping at the data, configuration, or service level.

CSegmentation of VlLNs

VLAN segmentation divides network broadcast domains and is a useful network control, but when all servers are already co-located in the same DMZ segment, VLANs do not address the higher-level concern of environment boundary enforcement.

DSubnetting of cloud environments

Subnetting of cloud environments is a cloud-specific network partitioning technique and is not applicable to on-premises servers residing within a shared DMZ.

Concept tested: Environment separation policy in shared network zones

Source: https://csrc.nist.gov/publications/detail/sp/800-125b/final

Topics

#environment separation#VLAN segmentation#DMZ#logical access controls

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice