nerdexam
CSA

CCSK · Question #205

ENISA: Which is not identified as a top security risk in ENISA research?

The correct answer is A. SQL Injection Attacks. ENISA's cloud computing risk assessment focuses on risks specific to or amplified by cloud architectures; SQL Injection is a general web application vulnerability not listed as a top cloud-specific risk.

Cloud Platform and Infrastructure Security

Question

ENISA: Which is not identified as a top security risk in ENISA research?

Options

  • ASQL Injection Attacks
  • BManagement Interface Compromise
  • CIsolation Failure
  • DLoss of Governance
  • EInsecure or Incomplete Data Deletion

How the community answered

(43 responses)
  • A
    79% (34)
  • B
    2% (1)
  • C
    2% (1)
  • D
    9% (4)
  • E
    7% (3)

Why each option

ENISA's cloud computing risk assessment focuses on risks specific to or amplified by cloud architectures; SQL Injection is a general web application vulnerability not listed as a top cloud-specific risk.

ASQL Injection AttacksCorrect

SQL Injection is an application-layer attack class that predates cloud computing and is not unique to or amplified by cloud architectures. ENISA's cloud risk research specifically identifies risks that arise from or are exacerbated by the cloud model itself, such as multi-tenancy isolation failures and loss of customer governance, making SQL Injection out of scope for that top-risk list.

BManagement Interface Compromise

Management Interface Compromise is an ENISA-identified top cloud risk because cloud management APIs and portals expose a broad attack surface that can grant control over entire customer environments if compromised.

CIsolation Failure

Isolation Failure is a top ENISA-identified cloud risk specific to multi-tenant architectures, where a breakdown in separation can expose one tenant's data or compute resources to another.

DLoss of Governance

Loss of Governance is one of ENISA's primary identified cloud risks, occurring when customers transfer control over their data and infrastructure to a provider and lose the ability to enforce their own security policies.

EInsecure or Incomplete Data Deletion

Insecure or Incomplete Data Deletion is an ENISA-identified top cloud risk because data may persist on shared storage media after a tenant requests deletion, due to the distributed and redundant nature of cloud storage systems.

Concept tested: ENISA top cloud computing security risks identification

Source: https://www.enisa.europa.eu/publications/cloud-computing-risk-assessment

Topics

#ENISA#cloud security risks#isolation failure#loss of governance

Community Discussion

No community discussion yet for this question.

Full CCSK Practice