exam questions

Exam PT1-002 All Questions

View all questions & answers for the PT1-002 exam

Exam PT1-002 topic 1 question 110 discussion

Actual exam question from CompTIA's PT1-002
Question #: 110
Topic #: 1
[All PT1-002 Questions]

A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical resources. Which of the following attack types is MOST concerning to the company?

  • A. Data flooding
  • B. Session riding
  • C. Cybersquatting
  • D. Side channel
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RVP20
Highly Voted 3 years, 1 month ago
Selected Answer: D
I'm not sure but ( D ) make more sense .
upvoted 6 times
...
tahagoksoy
Highly Voted 3 years, 2 months ago
The answer is D here since the clients are sharing the same physical resources
upvoted 5 times
Adonist
3 years, 1 month ago
Agreed
upvoted 2 times
...
...
bieecop
Most Recent 2 years, 5 months ago
Selected Answer: D
D That's correct.
upvoted 3 times
...
gblsx
2 years, 6 months ago
Selected Answer: A
I think it is Data flooding. If multiple companies are sharing the same physical resources and one company falls victim to a DDOS attack, the resources will be exhausted. Therefore, other companies will experience service issues as well.
upvoted 1 times
...
nudy
2 years, 6 months ago
Attacking the Cloud The cloud is vulnerable to the same types of attacks that affect many applications. An attack against a cloud delivery model such as Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) can result in a data breach. In addition to the financial impact of recovery fees and possible loss of intellectual property, a company that suffers from an attack can face fines, penalties, and legal action. As a result, it’s important to recognize the cloud computing infrastructure is susceptible to several types of attacks that include: Side-channel attacks: Also called a sidebar or implementation attack, this exploit is possible because of the shared nature of the cloud infrastructure, especially in a PaaS model. In this attack, the hardware leaks sensitive information such as cryptographic keys, via a covert channel, to a potential attacker.
upvoted 4 times
...
ResStapler
2 years, 8 months ago
D: Side Channel - makes the most sense. Cross-VM Cache Side Channel Attacks make it Vulnerable: One of the most sophisticated forms of attack is the cross-VM cache side channel attack that exploits shared cache memory between VMs. A cache side channel attack results in side channel data leakage, such as cryptographic keys. In cases where there exist shared hardware resources, the side channel attack exploits information obtained from the usage of, for example, Central Processing Unit (CPU) core and high level cache memory as opposed to exploiting theoretical weaknesses like the brute force attack. Ref: https://arxiv.org/pdf/1606.01356.pdf
upvoted 4 times
...
Hashlife
3 years ago
This is D "Additionally, they may also be used against virtual machines (VMs) and in cloud computing environments where an attacker and target share the same physical hardware." https://www.techtarget.com/searchsecurity/definition/side-channel-attack#:~:text=Side%2Dchannel%20attacks%20can%20even,share%20the%20same%20physical%20hardware.
upvoted 4 times
...
Davar39
3 years, 4 months ago
Answer is correct, link is dead but you can find the info on the following. https://www.alertlogic.com/blog/top-cloud-vulnerabilities/
upvoted 3 times
Adonist
3 years, 1 month ago
Session Hijacking doesn't have anything to do with shared cloud resources, so I don't think this is right. I think it should be D.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago