312-50V13 · Question #414
Thomas, a cloud security professional, is performing security assessment on cloud services to identify any loopholes. He detects a vulnerability in a bare-metal cloud server that can enable hackers…
The correct answer is C. Cloudborne attack. The scenario describes a vulnerability in a bare-metal cloud server that allows persistent firmware backdoors even after reallocation, which is characteristic of a Cloudborne attack.
Question
Options
- AMan-in-the-cloud (MITC) attack
- BCloud cryptojacking
- CCloudborne attack
- DMetadata spoofing attack
How the community answered
(37 responses)- A3% (1)
- B5% (2)
- C89% (33)
- D3% (1)
Why each option
The scenario describes a vulnerability in a bare-metal cloud server that allows persistent firmware backdoors even after reallocation, which is characteristic of a Cloudborne attack.
A Man-in-the-cloud (MITC) attack typically involves compromising cloud storage synchronization tokens to gain unauthorized access to cloud data, not firmware backdoors on bare-metal servers.
Cloud cryptojacking involves using a victim's cloud resources to mine cryptocurrency without their permission, rather than implanting firmware backdoors.
A Cloudborne attack specifically refers to a scenario where attackers can inject persistent backdoors into the firmware of bare-metal cloud servers, which then remain active even after the server is wiped and reallocated to new customers. This attack vector targets the underlying hardware and firmware of cloud infrastructure for long-term persistence.
Metadata spoofing attack involves manipulating or forging metadata to gain unauthorized access or bypass security controls, which is distinct from exploiting server firmware.
Concept tested: Cloudborne attack on bare-metal server firmware
Topics
Community Discussion
No community discussion yet for this question.