CAS-001 · Question #101
A security architect is seeking to outsource company server resources to a commercial cloud service provider. The provider under consideration has a reputation for poorly controlling physical access…
The correct answer is C. The likelihood a malicious user will obtain proprietary information by gaining local access to the. The scenario describes a cloud provider with two critical weaknesses: poor physical access controls and the practice of placing multiple clients' VMs on the same physical hardware (multi-tenancy). These two factors combine to create a specific risk: a malicious actor who gains…
Question
A security architect is seeking to outsource company server resources to a commercial cloud service provider. The provider under consideration has a reputation for poorly controlling physical access to datacenters and has been the victim of multiple social engineering attacks. The service provider regularly assigns VMs from multiple clients to the same physical resources. When conducting the final risk assessment which of the following should the security architect take into consideration?
Options
- AThe ability to implement user training programs for the purpose of educating internal staff about
- BThe cost of resources required to relocate services in the event of resource exhaustion on a particular
- CThe likelihood a malicious user will obtain proprietary information by gaining local access to the
- DAnnual loss expectancy resulting from social engineering attacks against the cloud service provider
How the community answered
(23 responses)- A22% (5)
- B4% (1)
- C61% (14)
- D13% (3)
Explanation
The scenario describes a cloud provider with two critical weaknesses: poor physical access controls and the practice of placing multiple clients' VMs on the same physical hardware (multi-tenancy). These two factors combine to create a specific risk: a malicious actor who gains physical access to the datacenter could exploit the shared physical resources to extract proprietary data from co-hosted VMs - a threat known as a VM escape or side-channel attack (e.g., cache-timing attacks like Spectre/Meltdown). This is the highest-priority risk to assess given the described environment. Option A (user training) addresses internal staff, not cloud provider risks. Option B (relocation cost) is a business continuity concern, not the most critical security risk. Option D (ALE from social engineering) is a valid metric but is a calculation derived from other assessments, not the primary risk factor to take into consideration when the multi-tenancy data leakage threat is so direct and specific.
Topics
Community Discussion
No community discussion yet for this question.