Courseiva
hardMultiple Choice

220-1202 Practice Question: A technician is investigating a security incident…

A technician is investigating a security incident where a user's virtual machine was compromised. The technician suspects that the VM was infected with malware that spread from the host. Which virtualization security best practice would have prevented this?

⚠ Common exam trap

CompTIA often tests the misconception that Type 2 hypervisors provide better isolation than Type 1 hypervisors, when in fact Type 1 (bare-metal) hypervisors offer stronger security boundaries because they run directly on hardware without a host OS layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Keep the hypervisor and host OS updated with security patches.

Keeping the hypervisor and host OS updated with security patches is a fundamental virtualization security best practice that prevents malware from exploiting known vulnerabilities in the hypervisor layer. In this scenario, the malware spread from the host to the VM, indicating a hypervisor-level compromise that patching would have mitigated. Regular patching closes the attack vector that allows host-to-VM infection, such as vulnerabilities in the hypervisor's management interface or device emulation code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable snapshots for all VMs.

    Why it's wrong here

    Snapshots are for backup and recovery, not for preventing malware spread between host and VM.

  • ✗

    Use a Type 2 hypervisor for better isolation.

    Why it's wrong here

    Type 2 hypervisors actually have a larger attack surface because they run on an OS, making them more vulnerable to VM escape attacks.

  • ✓

    Keep the hypervisor and host OS updated with security patches.

    Why this is correct

    Regular updates patch vulnerabilities that could be exploited for VM escape, preventing malware from spreading between host and VM.

  • ✗

    Assign more virtual CPUs to the VM.

    Why it's wrong here

    Assigning more vCPUs does not affect security; it only impacts performance.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.