CAS-003 · Question #333
An organization is considering the use of a thin client architecture as it moves to a cloud-hosted environment. A security analyst is asked to provide thoughts on the security advantages of using…
The correct answer is B. Thin client workstations require much less security because they lack storage and peripherals. Thin clients have a reduced security footprint because they lack local persistent storage and peripherals, minimizing the local attack surface that must be managed and secured.
Question
An organization is considering the use of a thin client architecture as it moves to a cloud-hosted environment. A security analyst is asked to provide thoughts on the security advantages of using thin clients and virtual workstations. Which of the following are security advantages of the use of this combination of thin clients and virtual workstations?
Options
- AMalicious insiders will not have the opportunity to tamper with data at rest and affect the integrity
- BThin client workstations require much less security because they lack storage and peripherals
- CAll thin clients use TPM for core protection, and virtual workstations use vTPM for core protection
- DMalicious users will have reduced opportunities for data extractions from their physical thin client
How the community answered
(38 responses)- A8% (3)
- B87% (33)
- C3% (1)
- D3% (1)
Why each option
Thin clients have a reduced security footprint because they lack local persistent storage and peripherals, minimizing the local attack surface that must be managed and secured.
Malicious insiders still have access to data through their virtual session and can tamper with or corrupt data through authorized or unauthorized actions within the virtual environment.
Thin clients offload processing and storage to centralized virtual workstations or servers, meaning there is no significant local data at rest to protect and fewer hardware vectors for malware persistence or physical attack. This inherently reduces the number and complexity of security controls required at each endpoint. The combination with virtual workstations also centralizes security enforcement to the data center rather than distributing it across every physical device.
Not all thin clients include a Trusted Platform Module, and asserting universal TPM adoption across all thin client hardware is a factual overgeneralization.
While local physical extraction is reduced, malicious users can still exfiltrate data via network transfers, clipboard sharing, or screen capture mechanisms available through the virtual session itself.
Concept tested: Security advantages of thin client and virtual workstation architecture
Source: https://csrc.nist.gov/publications/detail/sp/800-46/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.