nerdexam
CompTIA

PT0-002 · Question #55

A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical…

The correct answer is D. Side channel. Cross-VM Cache Side Channel Attacks make it Vulnerable: One of the most sophisticated forms of attack is the cross-VM cache side channel attack that exploits shared cache memory between VMs. A cache side channel attack results in side channel data leakage, such as cryptographic…

Attacks and Exploits

Question

A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical resources. Which of the following attack types is MOST concerning to the company?

Options

  • AData flooding
  • BSession riding
  • CCybersquatting
  • DSide channel

How the community answered

(37 responses)
  • A
    5% (2)
  • C
    3% (1)
  • D
    92% (34)

Explanation

Cross-VM Cache Side Channel Attacks make it Vulnerable: One of the most sophisticated forms of attack is the cross-VM cache side channel attack that exploits shared cache memory between VMs. A cache side channel attack results in side channel data leakage, such as cryptographic keys. In cases where there exist shared hardware resources, the side channel attack exploits information obtained from the usage of, for example, Central Processing Unit (CPU) core and high level cache memory as opposed to exploiting theoretical weaknesses like the brute force attack. Ref: https://arxiv.org/pdf/1606.01356.pdf

Topics

#Side-channel attack#Cloud security#Virtualization#Multi-tenancy

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice