nerdexam
CompTIA

CAS-001 · Question #147

A company runs large computing jobs only during the overnight hours. To minimize the amount of capital investment in equipment, the company relies on the elastic computing services of a major cloud…

The correct answer is D. Data scraped from the hardware platforms. When virtual machines are created and destroyed across a shared physical infrastructure, data remanence is a significant risk. Residual data (in memory, swap space, or storage) from one tenant's workload can potentially be scraped or recovered by a subsequent tenant or a…

Enterprise Security

Question

A company runs large computing jobs only during the overnight hours. To minimize the amount of capital investment in equipment, the company relies on the elastic computing services of a major cloud computing vendor. Because the virtual resources are created and destroyed on the fly across a large pool of shared resources, the company never knows which specific hardware platforms will be used from night to night. Which of the following presents the MOST risk to confidentiality in this scenario?

Options

  • ALoss of physical control of the servers
  • BDistribution of the job to multiple data centers
  • CNetwork transmission of cryptographic keys
  • DData scraped from the hardware platforms

How the community answered

(48 responses)
  • A
    8% (4)
  • B
    15% (7)
  • C
    4% (2)
  • D
    73% (35)

Explanation

When virtual machines are created and destroyed across a shared physical infrastructure, data remanence is a significant risk. Residual data (in memory, swap space, or storage) from one tenant's workload can potentially be scraped or recovered by a subsequent tenant or a malicious insider who gains access to the underlying hardware. This is a unique and serious confidentiality risk in multi-tenant cloud environments that the company has no control over, since they never know which physical hardware is used. Option A (loss of physical control) is a general cloud concern but is less specific. Option B (distribution across data centers) is manageable. Option C (network transmission of cryptographic keys) is a risk but is mitigated by using standard secure transport protocols.

Topics

#cloud security#data remanence#shared hardware#confidentiality

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice