CAS-005 · Question #316
Which of the following security risks should be considered as an organization reduces cost and increases availability of services by adopting serverless computing?
The correct answer is A. Level of control and influence governments have over cloud service providers. When adopting serverless computing, organizations must consider the geopolitical risk stemming from the control and influence governments might exert over their chosen cloud service providers, which can impact data sovereignty and compliance.
Question
Which of the following security risks should be considered as an organization reduces cost and increases availability of services by adopting serverless computing?
Options
- ALevel of control and influence governments have over cloud service providers
- BType of virtualization or emulation technology used in the provisioning of services
- CVertical scalability of the infrastructure underpinning the serverless offerings
- DUse of third-party monitoring of service provisioning and configurations
How the community answered
(16 responses)- A69% (11)
- B19% (3)
- C6% (1)
- D6% (1)
Why each option
When adopting serverless computing, organizations must consider the geopolitical risk stemming from the control and influence governments might exert over their chosen cloud service providers, which can impact data sovereignty and compliance.
The level of control and influence governments have over cloud service providers (CSPs) is a significant security risk for serverless computing, as it can affect data residency, compliance with various national laws, and the potential for government access to data, which is a concern for organizations with sensitive data or operations in multiple jurisdictions.
The specific virtualization or emulation technology used by the CSP is generally an implementation detail managed by the provider and less of a direct security risk for the organization consuming serverless services, which focuses on the abstraction layer.
Vertical scalability is a characteristic of the underlying infrastructure that supports serverless, which is managed by the CSP and is more related to performance and cost than a direct security risk for the organization.
The use of third-party monitoring can be a security benefit if it enhances visibility, or a risk if the third party is untrusted; however, it's not a fundamental risk inherent to the adoption of serverless computing itself like government influence.
Concept tested: Serverless computing security risks, geopolitical risk, data sovereignty
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/data-residency-overview?view=o365-worldwide
Community Discussion
No community discussion yet for this question.