Infrastructure Security and Virtualization Flashcards
6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Infrastructure Security and Virtualization flashcards as text
What is a 'hypervisor escape' attack and why is it particularly dangerous in cloud environments?
Answer: An attack where malicious code breaks out of a VM to access the hypervisor and other VMs on the same host
Hypervisor escape allows malware from one tenant's VM to break through to the hypervisor layer, potentially accessing other tenants' VMs on the same physical host.
According to CCSK, what is 'network segmentation' in virtual cloud environments used to achieve?
Answer: Isolating workloads to limit blast radius if one segment is compromised
Network segmentation isolates workloads so that a breach in one segment cannot easily spread laterally to other parts of the environment.
What security benefit do 'dedicated hosts' or 'dedicated instances' provide in public cloud?
Answer: Physical isolation from other customers' workloads, eliminating multi-tenancy risks at the hardware level
Dedicated hosts provide a physical server used exclusively by one customer, eliminating the risk of cross-tenant data leakage through shared hardware.
What is 'VM sprawl' and what security risk does it create in cloud environments?
Answer: The spread of unpatched virtual machines that are difficult to track and manage, creating unmanaged attack surfaces
VM sprawl results in orphaned, unpatched VMs that are forgotten but still running, creating entry points for attackers that are outside normal patching and monitoring.
According to CCSK, what is a 'golden image' and how does it contribute to infrastructure security?
Answer: A hardened, pre-approved VM or container image that serves as the baseline for all deployments
A golden image is a security-hardened, pre-approved template ensuring all deployed instances start from a known secure state rather than default configurations.
What is the primary security concern with 'live migration' of virtual machines in cloud environments?
Answer: VM memory contents, potentially including sensitive data and keys, are transmitted between hosts during migration
During live migration, VM memory (which may contain encryption keys, passwords, or sensitive data) is transmitted between physical hosts, creating an interception risk.