正解:B
One of the biggest challenges incloud security risk assessmentisthe lack of transparencyregardingcloud provider operations and security controls.
Key Issues with Limited Visibility:
* Cloud providers manage infrastructure at a global scale:
* Customerscannot directly inspectsecurity implementations.
* Rely onthird-party attestationslikeSOC 2, ISO 27001, CSA STARinstead of direct assessments.
* Multi-tenancy complexities:
* Cloud customersshare infrastructurewith other tenants.
* Data isolation mechanisms (e.g., virtual private clouds, encryption)must be trustedwithout direct verification.
* Regulatory compliance challenges:
* Organizations handling sensitive data (e.g., healthcare, finance)requirestrict controls.
* Cloud providers may not offer sufficient audit logsor control overdata residency and processing.
* Incident response limitations:
* In traditional IT, organizations controllog access, forensic analysis, and recovery.
* In the cloud,incident investigation depends on the provider's logging and notification practices.
Thisvisibility issueis extensively covered in:
* CCSK v5 - Security Guidance v4.0, Domain 4 (Compliance and Audit Management)
* ENISA's Cloud Computing Risk Assessment (Limited visibility into cloud provider security policies)