CCSK · Question #153
CCM: A hypothetical company called "lnfrastructure4Sure" provides Infrastructure as a Service (IaaS) to its clients. A customer wants to review Infrastructure4Sure's hypervisor security…
The correct answer is E. A and D. IaaS providers must secure hypervisors by minimizing attack surface through a smaller footprint and by continuously monitoring hypervisor logs for indicators of compromise.
Question
CCM: A hypothetical company called "lnfrastructure4Sure" provides Infrastructure as a Service (IaaS) to its clients. A customer wants to review Infrastructure4Sure's hypervisor security implementation measures. Which of the following measures should Infrastructure4Sure implement?
Options
- AChoose a hypervisor with a smaller footprint for a reduced attack surface.
- BHarden the hypervisor's configuration to increase areas of vulnerability (e.g., disabling memory
- CConnect unused physical hardware devices and enable clipboard or file-sharing services.
- DMonitor for signs of compromise by analyzing hypervisor logs on an ongoing basis.
- EA and D
How the community answered
(37 responses)- B8% (3)
- C5% (2)
- D3% (1)
- E84% (31)
Why each option
IaaS providers must secure hypervisors by minimizing attack surface through a smaller footprint and by continuously monitoring hypervisor logs for indicators of compromise.
Choosing a smaller-footprint hypervisor is a correct security measure but is incomplete on its own - it must be paired with monitoring controls such as log analysis to satisfy CCM requirements.
Hardening configuration should reduce areas of vulnerability, not increase them; disabling memory protections actively weakens hypervisor security and contradicts both CCM guidance and security best practices.
Connecting unused physical hardware and enabling clipboard or file-sharing services expands the attack surface, directly contradicting the principle of minimizing exposure in a secure IaaS hypervisor implementation.
Monitoring hypervisor logs is a correct detective control but is insufficient alone; it must be combined with preventive measures like footprint reduction (A) to address CCM hypervisor security requirements.
Selecting a hypervisor with a smaller footprint (A) reduces the exposed code base and available attack surface, directly limiting exploitation opportunities. Ongoing analysis of hypervisor logs (D) enables detection of anomalous behavior or active compromise. The CSA CCM requires both preventive and detective controls for hypervisor security in IaaS environments, making E the complete and correct answer.
Concept tested: CSA CCM IaaS hypervisor security implementation measures
Source: https://cloudsecurityalliance.org/research/cloud-controls-matrix
Topics
Community Discussion
No community discussion yet for this question.