A technician is deploying a new virtual machine on a Type 1 hypervisor. The VM will run a Linux web server and needs to be isolated from the corporate network except for HTTPS traffic. Which networking configuration should the technician implement?
Host-only mode creates a private virtual network between the VM and the host machine, completely isolating the VM from the external corporate network. This ensures the VM cannot be directly accessed or discovered by other devices on the corporate network. Configuring port forwarding specifically for HTTPS (port 443) on the host allows only this designated traffic to pass from the host to the isolated VM, precisely meeting the requirement for secure, controlled inbound access while maintaining maximum isolation.
Why this answer
A host-only virtual switch creates an isolated network between the host and the VM, preventing direct access from the corporate network. By configuring port forwarding on the host, the technician can selectively allow only HTTPS traffic (TCP/443) to reach the VM while keeping it otherwise isolated. This meets the requirement of isolation except for HTTPS.
Exam trap
In CompTIA A+ exams, candidates often confuse host-only and NAT networking modes, mistakenly thinking NAT alone provides inbound access, but NAT without port forwarding only allows outbound connections.
How to eliminate wrong answers
Option A is wrong because bridging the VM directly to the physical network adapter would place the VM on the same Layer 2 broadcast domain as the corporate network, providing no isolation. Option C is wrong because a NAT network without port forwarding would allow the VM to initiate outbound connections but would not permit inbound HTTPS traffic from the corporate network, failing the requirement to allow HTTPS. Option D is wrong because assigning the VM an IP from the corporate DHCP scope would give the VM a routable corporate IP address, making it directly accessible from the corporate network and defeating the isolation requirement.