nerdexam
CompTIA

SY0-301 · Question #437

A financial company requires a new private network link with a business partner to cater for real- time and batched data flows. Which of the following activities should be performed by the IT…

The correct answer is B. Design review. A design review must be performed before establishing a new private network link to evaluate security architecture, data flow risks, and compliance requirements before implementation.

Security architecture

Question

A financial company requires a new private network link with a business partner to cater for real- time and batched data flows. Which of the following activities should be performed by the IT security staff member prior to establishing the link?

Options

  • ABaseline reporting
  • BDesign review
  • CCode review
  • DSLA reporting

How the community answered

(34 responses)
  • A
    18% (6)
  • B
    71% (24)
  • C
    3% (1)
  • D
    9% (3)

Why each option

A design review must be performed before establishing a new private network link to evaluate security architecture, data flow risks, and compliance requirements before implementation.

ABaseline reporting

Baseline reporting measures current system performance and is an ongoing operational activity, not a pre-implementation security task for establishing a new link.

BDesign reviewCorrect

A design review is the appropriate pre-implementation activity that allows IT security staff to evaluate the proposed network architecture, identify security gaps, assess data classification requirements for the real-time and batched flows, and ensure controls like encryption, access control, and monitoring are properly specified before the link is built, reducing costly redesign after deployment.

CCode review

A code review applies to software development artifacts and is not relevant to the establishment of a private network link between organizations.

DSLA reporting

SLA reporting measures performance against agreed service levels and is a post-implementation operational activity, not a pre-implementation security task.

Concept tested: Pre-implementation security design review for network links

Source: https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-security-policy-design

Topics

#design review#network security#third-party connectivity#security assessment

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice