ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A SaaS provider keeps customer analytics archives in cloud-based object storage while virtual machine images reside on block storage volumes. The security team is reviewing threats that are unique to each storage type. Which risk is most specific to the object storage tier and therefore requires additional controls compared with the block storage tier?
Accidentally granting public read or write access through misconfigured bucket or container policies.
Hypervisor memory scraping attacks that capture encryption keys from guest VMs.
Residual data remaining on detached block volumes that were not securely wiped.
Side-channel exploits against shared NVMe controllers in multi-tenant hosts.
Object storage services such as Amazon S3 or Azure Blob are typically accessed through Internet-facing REST APIs and are organized into buckets or containers governed by their own access policies. If those policies are misconfigured-such as granting public read or write permissions-every object in the bucket can become accessible to anyone on the Internet, causing large-scale data exposure. This type of misconfiguration is a well-known, object-storage-specific threat.
Block storage volumes, by contrast, are presented as private devices that must be explicitly attached to virtual machines within the cloud provider's network. They do not receive public endpoints and are controlled through separate volume-level or IAM permissions; hence, accidental Internet-wide exposure is far less likely. Their predominant risks instead include issues like residual data on improperly sanitized volumes or unmanaged snapshot proliferation.
Side-channel exploits and hypervisor memory scraping attack the shared compute layer, not storage services themselves. Therefore, the threat most specific to the object storage tier is accidental public exposure caused by insecure bucket or container access policies.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Can you explain what REST APIs are and how they relate to object storage?
Open an interactive chat with Bash
How do misconfigured bucket or container policies lead to data exposure?
Open an interactive chat with Bash
What security measures can be implemented to prevent misconfigurations in object storage?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .