nerdexam
CompTIA

CAS-003 · Question #393

A security administrator at a hospital has implemented a VDI infrastructure to improve the security of patient records The VDI solution is cloud based, while PHI is maintained on a local database…

The correct answer is D. Install a DLP solution on the database server. The auditor's concern is that a successful VM escape or privilege escalation in the cloud-based VDI environment could allow an attacker to traverse the VPN tunnel and access the PHI on the local database server. Installing a DLP (Data Loss Prevention) solution on the database…

Enterprise Security Architecture

Question

A security administrator at a hospital has implemented a VDI infrastructure to improve the security of patient records The VDI solution is cloud based, while PHI is maintained on a local database server A VPN allows the VDI infrastructure to maintain a persistent connection to the local server. The IT auditor is concerned the solution may not provide the required level of security due to the possibility of VM escape and privilege escalation attacks. Which of the following architectural changes would decrease exposure from a compromise of the VDI system?

Options

  • AImplement a batch processing model.
  • BImplement a CASB solution for the VDI infrastructure.
  • CUse a community cloud model dedicated to hospitals.
  • DInstall a DLP solution on the database server.

How the community answered

(18 responses)
  • A
    11% (2)
  • B
    6% (1)
  • C
    28% (5)
  • D
    56% (10)

Explanation

The auditor's concern is that a successful VM escape or privilege escalation in the cloud-based VDI environment could allow an attacker to traverse the VPN tunnel and access the PHI on the local database server. Installing a DLP (Data Loss Prevention) solution on the database server creates an independent layer of protection directly around the PHI. Even if the VDI is fully compromised, the DLP solution can detect and block unauthorized attempts to exfiltrate sensitive patient data, limiting the blast radius of a VDI compromise. A CASB (B) governs cloud application access but does not directly protect the local database from a compromised VDI system. A community cloud (C) changes the hosting model but doesn't reduce VM escape risk. Batch processing (A) could reduce persistent connectivity but doesn't directly address the PHI exposure risk on the database server.

Topics

#VDI security#VM escape#PHI protection#DLP

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice