mediumMultiple Choice
CAS-004 Practice Question: During a merger, two companies need to integrate…
During a merger, two companies need to integrate their networks securely. Company A uses RFC 1918 addresses (10.0.0.0/8) and Company B also uses 10.0.0.0/8. Which architectural solution prevents routing conflicts and maintains security?
⚠ Common exam trap
Test-takers frequently assume a site-to-site VPN (Option A) inherently resolves overlapping IPs, but VPNs only encrypt traffic—they do not translate addresses, so routing conflicts persist without NAT or renumbering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy network address translation (NAT) on the border routers to translate one company's addresses to a unique range
Both companies use the same RFC 1918 address space (10.0.0.0/8), which would cause routing conflicts if directly connected. Deploying NAT on the border routers translates one company's overlapping addresses to a unique range (e.g., 172.16.0.0/12 or a public IP block), eliminating IP collisions while maintaining security through stateful inspection or ACLs. This allows the merged networks to communicate without renumbering either company's internal infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a site-to-site VPN with no address translation
Why it's wrong here
Both sites use overlapping 10.0.0.0/8 space, so a site-to-site VPN without NAT leaves duplicate prefixes that routers cannot disambiguate, breaking connectivity. It is tempting because a plain VPN is the standard way to link two private networks securely when their address ranges do not overlap.
- ✗
Enable direct BGP peering between the two networks
Why it's wrong here
BGP peering advertises each side's 10.0.0.0/8, so both networks install conflicting routes to the same prefix and traffic is misdirected. Direct peering is intended for exchanging distinct, non-overlapping prefixes between autonomous systems, not for resolving duplicate RFC 1918 addressing.
- ✗
Implement a firewall between the networks and allow all traffic
Why it's wrong here
A firewall permitting all traffic does nothing about the overlapping 10.0.0.0/8 ranges, so hosts cannot distinguish local from remote destinations and routing breaks. NAT or re-addressing resolves the overlap. A permissive firewall suits integrating networks with non-overlapping, trusted address space.
- ✓
Deploy network address translation (NAT) on the border routers to translate one company's addresses to a unique range
Why this is correct
Overlapping RFC 1918 ranges cannot coexist in a routed topology, so NAT on the border routers rewrites one company's 10.0.0.0/8 addresses into a unique range. This removes the routing ambiguity while preserving address hiding and security at the boundary.
Visual reference
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.