CAS-001 · Question #11
Driven mainly by cost, many companies outsource computing jobs which require a large amount of processor cycles over a short duration to cloud providers. This allows the company to avoid a large…
The correct answer is A. Traces of proprietary data which can remain on the virtual machine and be exploited. When a company uses on-demand cloud provisioning and later de-provisions those resources, traces of proprietary data can remain on the underlying virtual machine disk images or storage volumes. If that VM image or storage block is later reallocated-even improperly-remnant data…
Question
Driven mainly by cost, many companies outsource computing jobs which require a large amount of processor cycles over a short duration to cloud providers. This allows the company to avoid a large investment in computing resources which will only be used for a short time. Assuming the provisioned resources are dedicated to a single company, which of the following is the MAIN vulnerability associated with on-demand provisioning?
Options
- ATraces of proprietary data which can remain on the virtual machine and be exploited
- BRemnants of network data from prior customers on the physical servers during a compute job
- CExposure of proprietary data when in-transit to the cloud provider through IPSec tunnels
- DFailure of the de-provisioning mechanism resulting in excessive charges for the resources
How the community answered
(22 responses)- A55% (12)
- B14% (3)
- C5% (1)
- D27% (6)
Explanation
When a company uses on-demand cloud provisioning and later de-provisions those resources, traces of proprietary data can remain on the underlying virtual machine disk images or storage volumes. If that VM image or storage block is later reallocated-even improperly-remnant data could be exposed or forensically recovered. Option B is eliminated by the question's own premise: the resources are dedicated to a single company, so no prior customer data exists on the physical servers. Option C is incorrect because IPSec encrypts data in transit, so it is not a vulnerability in this scenario. Option D describes a billing/cost problem, not a security vulnerability. The core risk of virtualization is that de-provisioning does not always guarantee secure erasure of stored data.
Topics
Community Discussion
No community discussion yet for this question.