nerdexam
CompTIA

CAS-001 · Question #507

Company XYZ provides hosting services for hundreds of companies across multiple industries including healthcare, education, and manufacturing. The security architect for company XYZ is reviewing a…

The correct answer is C. Company XYZ could be liable for disclosure of sensitive data from one hosted customer when. The core architectural concern for a multi-tenant hosting provider consolidating onto shared virtual infrastructure is cross-customer data disclosure, which creates direct regulatory liability especially in regulated industries like healthcare.

Enterprise Security

Question

Company XYZ provides hosting services for hundreds of companies across multiple industries including healthcare, education, and manufacturing. The security architect for company XYZ is reviewing a vendor proposal to reduce company XYZ's hardware costs by combining multiple physical hosts through the use of virtualization technologies. The security architect notes concerns about data separation, confidentiality, regulatory requirements concerning PII, and administrative complexity on the proposal. Which of the following BEST describes the core concerns of the security architect?

Options

  • AMost of company XYZ's customers are willing to accept the risks of unauthorized disclosure and
  • BThe availability requirements in SLAs with each hosted customer would have to be re- written to
  • CCompany XYZ could be liable for disclosure of sensitive data from one hosted customer when
  • DNot all of company XYZ's customers require the same level of security and the administrative

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    12% (4)
  • C
    64% (21)
  • D
    21% (7)

Why each option

The core architectural concern for a multi-tenant hosting provider consolidating onto shared virtual infrastructure is cross-customer data disclosure, which creates direct regulatory liability especially in regulated industries like healthcare.

AMost of company XYZ's customers are willing to accept the risks of unauthorized disclosure and

Customer willingness to accept risk is not a technical architectural concern - the security architect's job is to identify actual security and compliance risks, not to assume customer risk tolerance.

BThe availability requirements in SLAs with each hosted customer would have to be re- written to

Rewriting SLAs to reflect updated availability requirements is a contractual and operational consideration, not the primary security or regulatory liability risk the architect flagged regarding data confidentiality and separation.

CCompany XYZ could be liable for disclosure of sensitive data from one hosted customer whenCorrect

When customers from regulated industries such as healthcare share virtualized physical hosts, a hypervisor misconfiguration, VM escape vulnerability, or improper data segregation could expose one customer's PII or protected health information to another tenant. This makes Company XYZ directly liable for unauthorized disclosure and puts it in violation of regulations like HIPAA, which is the core risk the security architect identified under data separation, confidentiality, and regulatory compliance concerns.

DNot all of company XYZ's customers require the same level of security and the administrative

Administrative complexity from varying security requirements across customers is a secondary operational concern and does not capture the primary risk of regulatory liability for cross-tenant data disclosure.

Concept tested: Multi-tenant virtualization data separation and regulatory liability

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-125.pdf

Topics

#multi-tenant virtualization#data separation#PII regulatory compliance#hosting security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice