ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your company plans to migrate a high-value analytics application to a public IaaS provider. During risk analysis, the security team highlights the possibility that an attacker could exploit a hypervisor vulnerability to pivot from another tenant's virtual machine into yours. Which risk-mitigation strategy most directly reduces the likelihood of this specific threat?
Configure auto-scaling groups to terminate and relaunch instances that fail health checks
Request and use dedicated hosts that are reserved exclusively for your organization's virtual machines
Tighten security group rules to allow only HTTPS traffic inbound to the instances
Deploy host-based intrusion detection agents inside every virtual machine
Placing the workload on dedicated, single-tenant hosts removes the risk that a compromised, co-resident tenant can reach your virtual machines through a hypervisor escape. While host-based intrusion detection, restrictive security groups, and aggressive instance replacement all add security value, they do not eliminate exposure created by sharing the underlying hypervisor with untrusted tenants. Physical isolation at the host level directly addresses the threat of cross-tenant compromise via hypervisor vulnerabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of a hypervisor in cloud environments?
Open an interactive chat with Bash
What are dedicated hosts, and how do they improve cloud security?
Open an interactive chat with Bash
Why are security group rules and intrusion detection insufficient to prevent hypervisor-based attacks?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .