CAS-001 · Question #127
A process allows a LUN to be available to some hosts and unavailable to others. Which of the following causes such a process to become vulnerable?
The correct answer is D. Moving the HBA. LUN masking controls which storage LUNs are visible to which hosts by binding access permissions to the Host Bus Adapter (HBA) - specifically its World Wide Name (WWN) or iSCSI Qualified Name (IQN). The vulnerability is that masking trusts the HBA identity, not the physical…
Question
A process allows a LUN to be available to some hosts and unavailable to others. Which of the following causes such a process to become vulnerable?
Options
- ALUN masking
- BData injection
- CData fragmentation
- DMoving the HBA
How the community answered
(27 responses)- A4% (1)
- B15% (4)
- C7% (2)
- D74% (20)
Explanation
LUN masking controls which storage LUNs are visible to which hosts by binding access permissions to the Host Bus Adapter (HBA) - specifically its World Wide Name (WWN) or iSCSI Qualified Name (IQN). The vulnerability is that masking trusts the HBA identity, not the physical host. If an HBA is physically removed from an authorized host and installed in an unauthorized host, that unauthorized host inherits all the LUN access rights previously granted to the HBA. The LUN masking configuration does not change - the new host can now access LUNs it should not. This is a known weakness of pure LUN masking without additional host-based or zone-level controls. LUN masking itself (A) is the protective mechanism being described, not the vulnerability. Data injection (B) and data fragmentation (C) are unrelated storage attack vectors that do not specifically compromise the masking model.
Topics
Community Discussion
No community discussion yet for this question.