Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium
A financial institution is migrating its on-premises virtualized infrastructure to a public cloud IaaS environment. They are concerned about the security implications of sharing physical hardware with other tenants. Which security control offered by cloud providers directly addresses this concern by preventing unauthorized data leakage or interference between different virtual machines on the same physical host?
- AHardware Security Modules (HSMs)
- BVirtual Private Cloud (VPC)
- CDedicated Hosts
- DNetwork Access Control Lists (NACLs)
Show answer & explanationAnswer & explanation
Correct answer: C. Dedicated Hosts
Dedicated Hosts provide physical servers dedicated to a single customer, preventing multi-tenancy on the underlying hardware and addressing concerns about shared physical resources.
Why the other options are wrong
- A. HSMs provide secure storage for cryptographic keys but do not address physical hardware isolation for compute instances.
- B. VPC provides network isolation but does not guarantee isolation at the physical server level.
- D. NACLs control network traffic at the subnet level but do not segregate physical hardware.
Cloud Dedicated Hosts
A cloud offering that provides physical servers dedicated for your exclusive use, addressing concerns about multi-tenancy on the underlying hardware.
- Ensures physical isolation from other cloud tenants.
- Can help meet specific compliance requirements.
- Often more expensive than shared instances.
Memory trick: When you need your own space, get a DEDICATED HOST, so no one else can SHARE your physical server. Think of it as a private room in a shared hotel.