ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a security assessment of a multitenant IaaS environment that relies on bare-metal (Type-1) hypervisors, you discover that virtual machines from different customers may be scheduled to share the same physical CPU cores simultaneously, potentially exposing them to cache-based side-channel attacks such as Spectre or Prime+Probe. Without purchasing new hardware, which hypervisor configuration change would most effectively reduce this specific risk?
Configure vCPU pinning (CPU affinity) so each tenant's virtual machines are restricted to a dedicated set of physical cores.
Permit nested virtualization so customers can run their own hypervisors inside the guest OS.
Enable memory ballooning to let the hypervisor reclaim unused guest RAM.
Replace default drivers with paravirtualized network and storage drivers inside each guest.
Cache-based side-channel attacks rely on two VMs executing on the same physical core (or sibling hyper-threads) so they can observe timing differences in the shared L1/L2 cache. Configuring CPU affinity-sometimes called vCPU pinning-binds every vCPU belonging to one tenant to a dedicated set of physical cores. Because no other tenant's workload can be scheduled on those cores, there is no shared cache state to exploit, which sharply lowers the attack surface. Memory ballooning only reclaims guest RAM and does nothing for CPU cache isolation, paravirtualized drivers improve I/O efficiency but do not affect scheduling, and nested virtualization merely allows a guest to run its own hypervisor while still sharing the same underlying cores.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is vCPU pinning and how does it reduce risks in a multitenant IaaS environment?
Open an interactive chat with Bash
What are cache-based side-channel attacks, like Spectre or Prime+Probe?
Open an interactive chat with Bash
Why is memory ballooning not effective for preventing side-channel attacks?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .