ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A public IaaS provider is preparing for ISO/IEC 20000-1 certification. As part of its Information Security Management process, the service management team must define a measurable control objective that specifically mitigates the risk of tenant-to-tenant compromise through the shared virtualization layer. According to ISO/IEC 20000-1 clause 6.6 and aligned ITIL guidance, which control objective is MOST appropriate to add to the service management system?
Ensure every reported security incident is resolved within the response times defined in service level agreements.
Deploy all vendor-issued security patches to the hypervisor on every compute cluster within 30 days of release.
Conduct internal audits of all third-party supplier contracts at least once per quarter.
Review and re-approve privileged access to the service desk toolset no less than annually.
Tenant isolation in a multi-tenant cloud hinges on the integrity of the hypervisor; un-patched vulnerabilities can allow one tenant to escape its virtual machine and affect others. ISO/IEC 20000-1 requires that information security controls be appropriate to service risks and measurable for continual improvement. A time-bound requirement to deploy vendor hypervisor patches directly addresses this high-impact risk and can be tracked for compliance. While promptly resolving incidents, auditing suppliers, and reviewing administrative access are all useful practices, none target the specific cross-tenant threat created by virtualization vulnerabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of ISO/IEC 20000-1 certification?
Open an interactive chat with Bash
What is a hypervisor and its role in virtualization security?
Open an interactive chat with Bash
Why is patch management important for hypervisor security?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .