Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium

A cloud platform team is implementing a custom operating system image for their virtual machines. To enhance the integrity and trustworthiness of the boot process, they want to ensure that the OS kernel and boot components have not been tampered with before the VM starts. Which security control can achieve this by verifying the integrity of the boot chain?

  1. ADisk Encryption
  2. BVulnerability Scanning
  3. CSecure Boot / Measured Boot
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: C. Secure Boot / Measured Boot

Secure Boot and Measured Boot mechanisms verify the integrity of the boot components, including the firmware, boot loader, and operating system kernel, against a trusted baseline. If any component has been tampered with, the boot process can be stopped or reported, ensuring a trusted operating environment.

Why the other options are wrong

  • A. Disk Encryption protects data at rest but does not verify the integrity of the boot process itself.
  • B. Vulnerability Scanning identifies known weaknesses but doesn't prevent or detect real-time tampering of boot components.
  • D. An IDS monitors for malicious activity after the system has booted and is running, not during the boot process itself.

Measured Boot (Virtualization)

A security mechanism that cryptographically verifies the integrity of the entire boot chain, from firmware to OS kernel, ensuring that no unauthorized modifications have occurred before the system starts.

  • Uses a Trusted Platform Module (TPM) or virtual TPM.
  • Records hashes of boot components to a secure log.
  • Can prevent rootkits and other low-level malware from loading.

Memory trick: Measure twice, boot once, for a secure start.

More Cloud Platform and Infrastructure Security questions