Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium
A cloud platform team is implementing a custom operating system image for their virtual machines (VMs) to ensure a standardized and secure baseline. Before deploying these VMs, they need to verify that the OS kernel and boot process have not been tampered with and are cryptographically verified. Which virtualization security mechanism provides this assurance?
- ARuntime Application Self-Protection (RASP)
- BTrusted Platform Module (TPM) / Measured Boot
- CJust-in-Time (JIT) Access
- DNetwork Intrusion Detection System (NIDS)
Show answer & explanationAnswer & explanation
Correct answer: B. Trusted Platform Module (TPM) / Measured Boot
Trusted Platform Module (TPM) combined with Measured Boot provides a hardware-rooted chain of trust that verifies the integrity of the boot process and OS kernel before the system fully starts, ensuring no tampering has occurred.
Why the other options are wrong
- A. RASP protects the application at runtime, not the boot process or kernel integrity.
- C. JIT Access controls administrative privileges dynamically but does not verify system integrity at boot.
- D. NIDS monitors network traffic for threats and does not relate to boot integrity.
Measured Boot (Virtualization)
A security feature that uses a hardware root of trust (like a TPM) to measure and record the integrity of boot components and the OS kernel, verifying no tampering has occurred.
- Verifies integrity before the OS fully loads.
- Creates a cryptographic 'report' of the boot process.
- Protects against bootkits and rootkits.
Memory trick: Ensuring a VM's boot is clean is like having a bouncer check every guest's ID at the door. MEASURED BOOT, with a TPM, is that super strict bouncer making sure no one sneaks in.