CAS-002 · Question #285
A large organization that builds and configures every data center against distinct requirements loses efficiency, which results in slow response time to resolve issues. However, total uniformity…
The correct answer is D. Lack of diversity increases the impact of specific events or attacks. Consolidating to a single vendor or design eliminates architectural diversity, meaning one vulnerability or attack can compromise all systems simultaneously. This monoculture risk represents the greatest security threat from uniformity.
Question
A large organization that builds and configures every data center against distinct requirements loses efficiency, which results in slow response time to resolve issues. However, total uniformity presents other problems. Which of the following presents the GREATEST risk when consolidating to a single vendor or design solution?
Options
- ACompetitors gain an advantage by increasing their service offerings.
- BVendor lock in may prevent negotiation of lower rates or prices.
- CDesign constraints violate the principle of open design.
- DLack of diversity increases the impact of specific events or attacks.
How the community answered
(15 responses)- A7% (1)
- B13% (2)
- C7% (1)
- D73% (11)
Why each option
Consolidating to a single vendor or design eliminates architectural diversity, meaning one vulnerability or attack can compromise all systems simultaneously. This monoculture risk represents the greatest security threat from uniformity.
Competitors gaining market advantage is a business strategy concern, not a security risk resulting directly from infrastructure design consolidation.
Vendor lock-in affecting pricing negotiation is a financial and contractual risk, not a direct security risk arising from design uniformity.
The open design principle holds that security should not rely on obscurity - it is not directly violated by choosing a single vendor or uniform design.
Security architecture diversity is a core defense-in-depth principle ensuring that a single CVE, zero-day exploit, or targeted attack technique cannot simultaneously compromise every asset. When an entire infrastructure shares one vendor or design, the blast radius of any specific event becomes organization-wide. Maintaining heterogeneity across vendors and designs limits the scope of any single attack or failure, making lack of diversity the greatest risk introduced by full consolidation.
Concept tested: Security architecture diversity and monoculture risk
Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final
Topics
Community Discussion
No community discussion yet for this question.