CompTIA Security+ (SY0-501) — Question 606
An organization has decided to host its web application and database in the cloud. Which of the following BEST describes the security concerns for this decision?
Answer options
- A. Access to the organization's servers could be exposed to other cloud-provider clients.
- B. The cloud vendor is a new attack vector within the supply chain.
- C. Outsourcing the code development adds risk to the cloud provider.
- D. Vendor support will cease when the hosting platforms reach EOL.
Correct answer: B
Explanation
The correct answer is B because using a cloud vendor introduces potential vulnerabilities in the supply chain, making them a target for attackers. Option A is incorrect as while server access could be compromised, it is not the primary concern like the vendor's role in the supply chain. Option C is misleading since outsourcing code development does not directly relate to the cloud provider's security. Option D is irrelevant as vendor support ending is more about service continuity than a direct security concern.