nerdexam
CompTIA

CAS-003 · Question #96

A company provides on-demand cloud computing resources for a sensitive project. The company implements a fully virtualized datacenter and terminal server access with two- factor authentication for…

The correct answer is A. Both VMs were left unsecured and an attacker was able to exploit network vulnerabilities to. In this question, two virtual machines have been accessed by an attacker. The question is asking what is MOST likely to have occurred. It is common for operating systems to not be fully patched. Of the options given, the most likely occurrence is that the two VMs were not fully…

Enterprise Security Architecture

Question

A company provides on-demand cloud computing resources for a sensitive project. The company implements a fully virtualized datacenter and terminal server access with two- factor authentication for customer access to the administrative website. The security administrator at the company has uncovered a breach in data confidentiality. Sensitive data from customer A was found on a hidden directory within the VM of company B. Company B is not in the same industry as company A and the two are not competitors. Which of the following has MOST likely occurred?

Options

  • ABoth VMs were left unsecured and an attacker was able to exploit network vulnerabilities to
  • BA stolen two factor token was used to move data from one virtual guest to another host on the
  • CA hypervisor server was left un-patched and an attacker was able to use a resource exhaustion
  • DAn employee with administrative access to the virtual guests was able to dump the guest memory

How the community answered

(14 responses)
  • A
    43% (6)
  • B
    14% (2)
  • C
    36% (5)
  • D
    7% (1)

Explanation

In this question, two virtual machines have been accessed by an attacker. The question is asking what is MOST likely to have occurred. It is common for operating systems to not be fully patched. Of the options given, the most likely occurrence is that the two VMs were not fully patched allowing an attacker to access each of them. The attacker could then copy data from one VM and hide it in a hidden folder on the other

Topics

#cloud security#VM isolation#virtualization breach#data confidentiality

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice