nerdexam
EC-Council

312-50V13 · Question #414

Thomas, a cloud security professional, is performing security assessment on cloud services to identify any loopholes. He detects a vulnerability in a bare-metal cloud server that can enable hackers…

The correct answer is C. Cloudborne attack. The scenario describes a vulnerability in a bare-metal cloud server that allows persistent firmware backdoors even after reallocation, which is characteristic of a Cloudborne attack.

Submitted by miguelv· Mar 6, 2026Cloud Computing

Question

Thomas, a cloud security professional, is performing security assessment on cloud services to identify any loopholes. He detects a vulnerability in a bare-metal cloud server that can enable hackers to implant malicious backdoors in its firmware. He also identified that an installed backdoor can persist even if the server is reallocated to new clients or businesses that use it as an laaS. What is the type of cloud attack that can be performed by exploiting the vulnerability discussed in the above scenario?

Options

  • AMan-in-the-cloud (MITC) attack
  • BCloud cryptojacking
  • CCloudborne attack
  • DMetadata spoofing attack

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    89% (33)
  • D
    3% (1)

Why each option

The scenario describes a vulnerability in a bare-metal cloud server that allows persistent firmware backdoors even after reallocation, which is characteristic of a Cloudborne attack.

AMan-in-the-cloud (MITC) attack

A Man-in-the-cloud (MITC) attack typically involves compromising cloud storage synchronization tokens to gain unauthorized access to cloud data, not firmware backdoors on bare-metal servers.

BCloud cryptojacking

Cloud cryptojacking involves using a victim's cloud resources to mine cryptocurrency without their permission, rather than implanting firmware backdoors.

CCloudborne attackCorrect

A Cloudborne attack specifically refers to a scenario where attackers can inject persistent backdoors into the firmware of bare-metal cloud servers, which then remain active even after the server is wiped and reallocated to new customers. This attack vector targets the underlying hardware and firmware of cloud infrastructure for long-term persistence.

DMetadata spoofing attack

Metadata spoofing attack involves manipulating or forging metadata to gain unauthorized access or bypass security controls, which is distinct from exploiting server firmware.

Concept tested: Cloudborne attack on bare-metal server firmware

Topics

#cloud security#bare-metal server#firmware backdoor#Cloudborne attack#IaaS

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice