ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium
A system administrator is configuring a new server for a multi-tenant application. To enhance security and prevent one tenant's processes from directly accessing or corrupting the memory space of another tenant or the operating system kernel, which fundamental security capability of information systems should be properly implemented and configured?
- AData Loss Prevention (DLP)
- BMultifactor authentication (MFA)
- CMemory protection
- DNetwork segmentation
Show answer & explanationAnswer & explanation
Correct answer: C. Memory protection
Memory protection is a fundamental security capability that prevents a process from accessing memory that has not been allocated to it. This is crucial in multi-tenant environments to ensure that one tenant's application or processes cannot interfere with or read the memory of another tenant or the operating system kernel.
Why the other options are wrong
- A. DLP prevents sensitive data from leaving the organization, not memory corruption between processes.
- B. MFA protects user authentication, not memory access between processes.
- D. Network segmentation isolates network traffic, not memory segments on a single server.
Memory Protection
A mechanism that controls access rights to memory on a computer, preventing processes from accessing unauthorized memory regions.
- Crucial for operating system stability and security in multi-tasking environments.
- Protects against buffer overflows, unauthorized data access, and process interference.
- Implemented by hardware (MMU) and managed by the operating system.
Memory trick: Memory protection walls off processes like rooms in a house.