ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a security assessment of a public IaaS provider, you learn that customer virtual machines are routinely migrated off a host and the vacated blocks on a thin-provisioned shared SAN are re-allocated to other tenants within minutes. The provider confirms that it does not perform cryptographic erasure or zero-fill deleted virtual disks before reuse. Which risk should you rate as having the greatest likelihood and impact for your organization?
Compromise of management plane APIs by a malicious insider
Data remanence exposing residual information on shared storage after virtual disk deletion
Denial-of-service from a noisy neighbor exhausting host resources
Hypervisor escape allowing a malicious VM to compromise co-resident guests
Because virtual disk blocks are re-assigned to new tenants without cryptographic erasure or secure overwrite, residual data from your workloads can persist on the shared SAN. A subsequent tenant could potentially access that data through forensic techniques or misconfiguration, leading to unauthorized disclosure of sensitive information. This is the classic data remanence risk inherent in multitenant cloud storage. While hypervisor escape, management-plane abuse, and noisy-neighbor DoS are valid concerns, the scenario's specific control gap (lack of sanitization on media reuse) makes data remanence the most immediate and probable threat.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is data remanence?
Open an interactive chat with Bash
Why is cryptographic erasure important in cloud environments?
Open an interactive chat with Bash
What is thin provisioning, and how does it relate to data risks in cloud storage?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .