nerdexam
CompTIA

CAS-001 · Question #442

A large organization that builds and configures every data center against distinct requirements loses efficiency, which results in slow response time to resolve issues. However, total uniformity…

The correct answer is D. Lack of diversity increases the impact of specific events or attacks. Consolidating to a single vendor or design creates a monoculture risk. When every data center uses identical hardware, software, and configurations, a single vulnerability, firmware bug, or targeted attack has the potential to impact every system simultaneously. There is no…

Technical Integration of Enterprise Components

Question

A large organization that builds and configures every data center against distinct requirements loses efficiency, which results in slow response time to resolve issues. However, total uniformity presents other problems. Which of the following presents the GREATEST risk when consolidating to a single vendor or design solution?

Options

  • ACompetitors gain an advantage by increasing their service offerings.
  • BVendor lock in may prevent negotiation of lower rates or prices.
  • CDesign constraints violate the principle of open design.
  • DLack of diversity increases the impact of specific events or attacks.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    15% (3)
  • D
    70% (14)

Explanation

Consolidating to a single vendor or design creates a monoculture risk. When every data center uses identical hardware, software, and configurations, a single vulnerability, firmware bug, or targeted attack has the potential to impact every system simultaneously. There is no diversity to limit the blast radius. This is analogous to monoculture agriculture - a single pathogen can destroy the entire crop. Vendor lock-in (B) is a real business concern but represents a cost/flexibility problem, not a catastrophic security risk. Competitor advantage (A) is a business strategy issue, not a security risk. Open design (C) is a security principle about transparency, not applicable to multi-vendor vs. single-vendor decisions. The security community widely recognizes lack of diversity (D) as the greatest technical risk in homogeneous environments.

Topics

#vendor diversity#single point of failure#infrastructure risk#monoculture

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice