Courseiva
mediumMultiple Choice

CAS-004 Practice Question: During a merger, two companies need to integrate…

During a merger, two companies need to integrate their networks securely. Company A uses RFC 1918 addresses (10.0.0.0/8) and Company B also uses 10.0.0.0/8. Which architectural solution prevents routing conflicts and maintains security?

⚠ Common exam trap

Test-takers frequently assume a site-to-site VPN (Option A) inherently resolves overlapping IPs, but VPNs only encrypt traffic—they do not translate addresses, so routing conflicts persist without NAT or renumbering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy network address translation (NAT) on the border routers to translate one company's addresses to a unique range

Both companies use the same RFC 1918 address space (10.0.0.0/8), which would cause routing conflicts if directly connected. Deploying NAT on the border routers translates one company's overlapping addresses to a unique range (e.g., 172.16.0.0/12 or a public IP block), eliminating IP collisions while maintaining security through stateful inspection or ACLs. This allows the merged networks to communicate without renumbering either company's internal infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a site-to-site VPN with no address translation

    Why it's wrong here

    Both sites use overlapping 10.0.0.0/8 space, so a site-to-site VPN without NAT leaves duplicate prefixes that routers cannot disambiguate, breaking connectivity. It is tempting because a plain VPN is the standard way to link two private networks securely when their address ranges do not overlap.

  • ✗

    Enable direct BGP peering between the two networks

    Why it's wrong here

    BGP peering advertises each side's 10.0.0.0/8, so both networks install conflicting routes to the same prefix and traffic is misdirected. Direct peering is intended for exchanging distinct, non-overlapping prefixes between autonomous systems, not for resolving duplicate RFC 1918 addressing.

  • ✗

    Implement a firewall between the networks and allow all traffic

    Why it's wrong here

    A firewall permitting all traffic does nothing about the overlapping 10.0.0.0/8 ranges, so hosts cannot distinguish local from remote destinations and routing breaks. NAT or re-addressing resolves the overlap. A permissive firewall suits integrating networks with non-overlapping, trusted address space.

  • ✓

    Deploy network address translation (NAT) on the border routers to translate one company's addresses to a unique range

    Why this is correct

    Overlapping RFC 1918 ranges cannot coexist in a routed topology, so NAT on the border routers rewrites one company's 10.0.0.0/8 addresses into a unique range. This removes the routing ambiguity while preserving address hiding and security at the boundary.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.