nerdexam
CompTIA

CAS-002 · Question #209

Company XYZ provides hosting services for hundreds of companies across multiple industries including healthcare, education, and manufacturing. The security architect for company XYZ is reviewing a…

The correct answer is C. Company XYZ could be liable for disclosure of sensitive data from one hosted customer. Hosting customers from multiple regulated industries on shared virtualized infrastructure creates cross-tenant data disclosure risk and exposes the hosting provider to significant regulatory liability.

Enterprise Security

Question

Company XYZ provides hosting services for hundreds of companies across multiple industries including healthcare, education, and manufacturing. The security architect for company XYZ is reviewing a vendor proposal to reduce company XYZ's hardware costs by combining multiple physical hosts through the use of virtualization technologies. The security architect notes concerns about data separation, confidentiality, regulatory requirements concerning PII, and administrative complexity on the proposal. Which of the following BEST describes the core concerns of the security architect?

Options

  • AMost of company XYZ's customers are willing to accept the risks of unauthorized disclosure
  • BThe availability requirements in SLAs with each hosted customer would have to be re-written
  • CCompany XYZ could be liable for disclosure of sensitive data from one hosted customer
  • DNot all of company XYZ's customers require the same level of security and the administrative

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    23% (7)
  • C
    60% (18)
  • D
    10% (3)

Why each option

Hosting customers from multiple regulated industries on shared virtualized infrastructure creates cross-tenant data disclosure risk and exposes the hosting provider to significant regulatory liability.

AMost of company XYZ's customers are willing to accept the risks of unauthorized disclosure

Regulated customers such as healthcare organizations cannot simply accept unauthorized disclosure risks; legal frameworks like HIPAA impose mandatory protections regardless of a customer's stated risk tolerance.

BThe availability requirements in SLAs with each hosted customer would have to be re-written

SLA availability requirements may need updating, but this is a secondary operational concern compared to the immediate confidentiality and regulatory liability risk posed by cross-tenant data exposure.

CCompany XYZ could be liable for disclosure of sensitive data from one hosted customerCorrect

When customers from healthcare, manufacturing, and education share the same physical hosts through virtualization, a hypervisor vulnerability, misconfigured VLAN, or storage misconfiguration could allow one tenant's sensitive data to be accessed by another. This exposes Company XYZ to direct legal liability, particularly because healthcare customers are subject to HIPAA requirements for PHI/PII protection that the hosting provider must contractually and technically enforce. The core concern is that the provider becomes accountable for data separation failures that violate each customer's specific regulatory obligations.

DNot all of company XYZ's customers require the same level of security and the administrative

Differing security requirements and administrative complexity are real operational challenges but are secondary to the core concern of legal liability from cross-customer data disclosure in a regulated multi-tenant environment.

Concept tested: Multi-tenant virtualization data separation and regulatory liability

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-125A.pdf

Topics

#multi-tenant virtualization#data separation#PII compliance#cloud hosting liability

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice