Systems Security Certified Practitioner – SSCP – Question0419

What security problem is most likely to exist if an operating system permits objects to be used sequentially by multiple users without forcing a refresh of the objects?

A.
Disclosure of residual data.
B. Unauthorized obtaining of a privileged execution state.
C. Denial of service through a deadly embrace.
D. Data leakage through covert channels.

Correct Answer: A

Explanation:

This question is asking you to consider the effects of object reuse. Object reuse is “reassigning to subject media that previously contained information. Object reuse is a security concern because if insufficient measures were taken to erase the information on the media, the information may be disclosed to unauthorized personnel.”
This concept relates to Security Architecture and Design, because it is in level C2: Controlled Access Protection, of the Orange Book, where “The object reuse concept must be invoked, meaning that any medium holding data must not contain any remnants of information after it is release for another subject to use.”
REFERENCE:
AIO Version 5 (Shon Harris), page 360 and TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.