nerdexam
CompTIA

CAS-002 · Question #285

A large organization that builds and configures every data center against distinct requirements loses efficiency, which results in slow response time to resolve issues. However, total uniformity…

The correct answer is D. Lack of diversity increases the impact of specific events or attacks. Consolidating to a single vendor or design eliminates architectural diversity, meaning one vulnerability or attack can compromise all systems simultaneously. This monoculture risk represents the greatest security threat from uniformity.

Research and Analysis

Question

A large organization that builds and configures every data center against distinct requirements loses efficiency, which results in slow response time to resolve issues. However, total uniformity presents other problems. Which of the following presents the GREATEST risk when consolidating to a single vendor or design solution?

Options

  • ACompetitors gain an advantage by increasing their service offerings.
  • BVendor lock in may prevent negotiation of lower rates or prices.
  • CDesign constraints violate the principle of open design.
  • DLack of diversity increases the impact of specific events or attacks.

How the community answered

(15 responses)
  • A
    7% (1)
  • B
    13% (2)
  • C
    7% (1)
  • D
    73% (11)

Why each option

Consolidating to a single vendor or design eliminates architectural diversity, meaning one vulnerability or attack can compromise all systems simultaneously. This monoculture risk represents the greatest security threat from uniformity.

ACompetitors gain an advantage by increasing their service offerings.

Competitors gaining market advantage is a business strategy concern, not a security risk resulting directly from infrastructure design consolidation.

BVendor lock in may prevent negotiation of lower rates or prices.

Vendor lock-in affecting pricing negotiation is a financial and contractual risk, not a direct security risk arising from design uniformity.

CDesign constraints violate the principle of open design.

The open design principle holds that security should not rely on obscurity - it is not directly violated by choosing a single vendor or uniform design.

DLack of diversity increases the impact of specific events or attacks.Correct

Security architecture diversity is a core defense-in-depth principle ensuring that a single CVE, zero-day exploit, or targeted attack technique cannot simultaneously compromise every asset. When an entire infrastructure shares one vendor or design, the blast radius of any specific event becomes organization-wide. Maintaining heterogeneity across vendors and designs limits the scope of any single attack or failure, making lack of diversity the greatest risk introduced by full consolidation.

Concept tested: Security architecture diversity and monoculture risk

Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final

Topics

#vendor diversity#single point of failure#risk concentration#enterprise architecture

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice