nerdexam
CSA

CCSK · Question #153

CCM: A hypothetical company called "lnfrastructure4Sure" provides Infrastructure as a Service (IaaS) to its clients. A customer wants to review Infrastructure4Sure's hypervisor security…

The correct answer is E. A and D. IaaS providers must secure hypervisors by minimizing attack surface through a smaller footprint and by continuously monitoring hypervisor logs for indicators of compromise.

Cloud Platform and Infrastructure Security

Question

CCM: A hypothetical company called "lnfrastructure4Sure" provides Infrastructure as a Service (IaaS) to its clients. A customer wants to review Infrastructure4Sure's hypervisor security implementation measures. Which of the following measures should Infrastructure4Sure implement?

Options

  • AChoose a hypervisor with a smaller footprint for a reduced attack surface.
  • BHarden the hypervisor's configuration to increase areas of vulnerability (e.g., disabling memory
  • CConnect unused physical hardware devices and enable clipboard or file-sharing services.
  • DMonitor for signs of compromise by analyzing hypervisor logs on an ongoing basis.
  • EA and D

How the community answered

(37 responses)
  • B
    8% (3)
  • C
    5% (2)
  • D
    3% (1)
  • E
    84% (31)

Why each option

IaaS providers must secure hypervisors by minimizing attack surface through a smaller footprint and by continuously monitoring hypervisor logs for indicators of compromise.

AChoose a hypervisor with a smaller footprint for a reduced attack surface.

Choosing a smaller-footprint hypervisor is a correct security measure but is incomplete on its own - it must be paired with monitoring controls such as log analysis to satisfy CCM requirements.

BHarden the hypervisor's configuration to increase areas of vulnerability (e.g., disabling memory

Hardening configuration should reduce areas of vulnerability, not increase them; disabling memory protections actively weakens hypervisor security and contradicts both CCM guidance and security best practices.

CConnect unused physical hardware devices and enable clipboard or file-sharing services.

Connecting unused physical hardware and enabling clipboard or file-sharing services expands the attack surface, directly contradicting the principle of minimizing exposure in a secure IaaS hypervisor implementation.

DMonitor for signs of compromise by analyzing hypervisor logs on an ongoing basis.

Monitoring hypervisor logs is a correct detective control but is insufficient alone; it must be combined with preventive measures like footprint reduction (A) to address CCM hypervisor security requirements.

EA and DCorrect

Selecting a hypervisor with a smaller footprint (A) reduces the exposed code base and available attack surface, directly limiting exploitation opportunities. Ongoing analysis of hypervisor logs (D) enables detection of anomalous behavior or active compromise. The CSA CCM requires both preventive and detective controls for hypervisor security in IaaS environments, making E the complete and correct answer.

Concept tested: CSA CCM IaaS hypervisor security implementation measures

Source: https://cloudsecurityalliance.org/research/cloud-controls-matrix

Topics

#hypervisor security#attack surface reduction#IaaS provider controls#configuration hardening

Community Discussion

No community discussion yet for this question.

Full CCSK Practice