CCSK · Question #221
Which of the following is an underlying vulnerability related to loss of Governance?
The correct answer is D. Unclear asset ownership. Unclear asset ownership is a governance vulnerability because it creates ambiguity about accountability for managing, securing, and protecting cloud resources.
Question
Which of the following is an underlying vulnerability related to loss of Governance?
Options
- ALack of reputational isolation
- BLack of resource isolation
- CHypervisor vulnerabilities
- DUnclear asset ownership
- ELack of supplier redundancy
How the community answered
(47 responses)- A6% (3)
- B13% (6)
- C2% (1)
- D77% (36)
- E2% (1)
Why each option
Unclear asset ownership is a governance vulnerability because it creates ambiguity about accountability for managing, securing, and protecting cloud resources.
Lack of reputational isolation relates to multi-tenancy risks where one tenant's actions can negatively affect another's reputation, which is a multi-tenancy concern rather than a governance vulnerability.
Lack of resource isolation is a technical vulnerability related to shared infrastructure and multi-tenancy, not a governance breakdown.
Hypervisor vulnerabilities are technical security flaws in virtualization infrastructure and are categorized under technical, not governance, risk.
Loss of Governance in cloud environments frequently stems from unclear asset ownership, where neither the cloud provider nor the customer has defined responsibility for specific resources. Without clear ownership, security policies, patch management, and compliance obligations may go unaddressed. This is a core governance risk identified in frameworks such as the CSA Top Threats, which links governance loss directly to undefined roles and responsibilities over assets.
Lack of supplier redundancy is a business continuity and availability risk, not a governance-related vulnerability.
Concept tested: Cloud governance risks and asset ownership accountability
Source: https://cloudsecurityalliance.org/research/topics/top-threats
Topics
Community Discussion
No community discussion yet for this question.