312-50V12 · Question #324
Thomas, a cloud security professional, is performing security assessment on cloud services to identify any loopholes. He detects a vulnerability in a bare-metal cloud server that can enable hackers to
The correct answer is A. Cloudborne attack. The scenario describes a Cloudborne attack, which involves implanting persistent firmware backdoors on bare-metal cloud servers that survive reallocation to new clients.
Question
Options
- ACloudborne attack
- BMan-in-the-cloud (MITC) attack
- CMetadata spoofing attack
- DCloud cryptojacking
How the community answered
(22 responses)- A95% (21)
- B5% (1)
Why each option
The scenario describes a Cloudborne attack, which involves implanting persistent firmware backdoors on bare-metal cloud servers that survive reallocation to new clients.
A Cloudborne attack specifically targets the firmware of bare-metal servers in cloud environments, allowing malicious code to persist even after the server is wiped and reallocated to new clients, perfectly matching the scenario described.
A Man-in-the-cloud (MITC) attack involves leveraging compromised cloud storage synchronization services to intercept or manipulate data, not implanting firmware backdoors on bare-metal servers.
A metadata spoofing attack exploits cloud instance metadata services to gain unauthorized access or information within an instance, which is distinct from a bare-metal firmware vulnerability.
Cloud cryptojacking involves secretly using a victim's cloud computing resources to mine cryptocurrency without their consent, focusing on resource theft rather than firmware persistence.
Concept tested: Bare-metal server firmware compromise in cloud IaaS
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/trusted-launch-for-vms
Topics
Community Discussion
No community discussion yet for this question.