Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityHard
A cloud provider offers a platform-as-a-service (PaaS) database service. A customer wants to ensure that their data stored in this database is physically isolated from other customers' data at the storage layer. Which of the following isolation strategies would the customer MOST likely expect the CSP to implement to meet this physical isolation requirement?
- ADedicated physical storage arrays for each customer.
- BNetwork segmentation of database instances using VLANs.
- CLogical separation through database schemas and user roles.
- DEncryption of customer data with unique customer-managed keys.
Show answer & explanationAnswer & explanation
Correct answer: A. Dedicated physical storage arrays for each customer.
While logical separation (A), encryption (C), and network segmentation (D) are important security controls, the question specifically asks for *physical isolation at the storage layer*. Dedicated physical storage arrays or disks for each customer would be the most direct way to achieve true physical isolation of data, preventing any shared physical storage resources between tenants.
Why the other options are wrong
- B. Network segmentation isolates network traffic to and from the database, but it does not physically isolate the underlying storage where the data resides.
- C. Logical separation is crucial but does not provide *physical* isolation; data still resides on shared physical infrastructure.
- D. Encryption protects data confidentiality and integrity but does not provide *physical* isolation; encrypted data can still reside on shared physical storage.
Physical Data Isolation
Ensuring that one tenant's data resides on distinct physical hardware resources, preventing any sharing of underlying physical storage with other tenants.
- Achieved through dedicated hardware (disks, servers).
- Provides strongest form of isolation.
- More expensive and less common in multi-tenant cloud.
Memory trick: Physical disks for each tenant, like private vaults, no sharing meant.