Courseiva
hardMultiple Select

350-401 Practice Question: Which three statements about hypervisor security…

Which three statements about hypervisor security and isolation are true? (Choose three.)

⚠ Common exam trap

The trap here is the misconception that VMs are automatically secure due to isolation, leading candidates to overlook the need for hypervisor patching and hardening, or to assume VMs have direct hardware access when the hypervisor mediates all interactions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A VM escape attack occurs when an attacker breaks out of a virtual machine to access the hypervisor or other VMs.

Option A is correct because a VM escape is precisely the class of attack in which code running inside a guest breaks the virtualization boundary to reach the hypervisor or other guests, which is why hypervisor hardening matters. Option C is correct because the hypervisor (or VMM) is responsible for partitioning and enforcing isolation of memory, CPU, and I/O devices, typically via hardware-assisted virtualization features such as Intel VT-x/EPT or AMD-V/RVI, so one VM cannot read or write another VM's data. Option D is correct because the hypervisor is a high-value attack surface, so applying vendor patches and minimizing exposed services and virtual devices (reducing attack surface) are standard hardening practices. Option B is wrong because VMs are only isolated if the hypervisor and its configuration are secure; they are not inherently safe and still need patching, monitoring, and access controls. Option E is wrong because guest VMs access virtualized hardware presented by the hypervisor, not the physical CPU and memory directly, which is what enables the isolation the hypervisor enforces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A VM escape attack occurs when an attacker breaks out of a virtual machine to access the hypervisor or other VMs.

    Why this is correct

    A VM escape exploits a hypervisor or virtualisation flaw so code running inside a guest breaks containment, reaching the hypervisor or neighbouring VMs. This is precisely the definition the stem requires: breaking out of a virtual machine to access the hypervisor or other VMs.

  • ✗

    Virtual machines are inherently isolated from each other and do not require any additional security measures.

    Why it's wrong here

    Hypervisor isolation separates guests but does not remove the need for patching, guest hardening, network segmentation or monitoring, so no additional measures is false. It tempts because VM boundaries do prevent one guest from reading another's memory, which is the correct answer only when the question asks what isolation itself provides.

  • ✓

    The hypervisor must enforce memory and device isolation to prevent one VM from accessing another VM's data.

    Why this is correct

    Isolation depends on the hypervisor mediating memory access and device I/O, typically via second-level address translation and IOMMU partitioning, so a guest cannot read another guest's memory or devices. This satisfies the stem's requirement that isolation prevents one VM accessing another's data.

  • ✓

    Regularly patching the hypervisor and reducing its attack surface are important security practices.

    Why this is correct

    The hypervisor is a high-value attack target, so applying vendor patches promptly and disabling unused virtual hardware, services and management interfaces shrinks exploitable surface. This directly satisfies the stem's statement that patching and reducing attack surface are important hypervisor security practices.

  • ✗

    Virtual machines have direct access to physical hardware resources such as CPU and memory.

    Why it's wrong here

    Virtual machines access hardware only through the hypervisor's emulated or paravirtualised devices, never directly, which is what enforces isolation between guests. It tempts because VMs do consume physical CPU and memory, but direct hardware access describes passthrough configurations rather than the standard virtualised model.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.