Courseiva
mediumMultiple Choice

CAS-004 Practice Question: A virtualization administrator needs to ensure…

A virtualization administrator needs to ensure that virtual machines (VMs) from different customers cannot communicate with each other unless explicitly allowed. Which network security control should be implemented on the hypervisor?

⚠ Common exam trap

CAS-005 often tests whether candidates confuse host-hardening controls (patching) with network-isolation controls (virtual firewalls) — the question's emphasis on 'cannot communicate' points to segmentation, not patching.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a virtual firewall to create per-VM security groups

A virtual firewall applied at the hypervisor level can enforce per-VM security groups, micro-segmentation, and explicit allow rules between VMs, which is exactly what is needed to prevent cross-customer communication unless permitted. This is the standard control for multi-tenant isolation at the virtualization layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patch the hypervisor regularly

    Why it's wrong here

    Patching the hypervisor addresses vulnerabilities in the virtualisation layer itself, not the routing of traffic between guest virtual NICs. It is tempting because patching is a core hardening task, and would be correct for remediating a known hypervisor escape or privilege-escalation flaw.

  • ✗

    Assign each VM to a different physical server

    Why it's wrong here

    Physical separation prevents inter-VM traffic only by removing shared hosting, not by a hypervisor control, and it breaks the requirement to allow explicit communication. It is tempting as an isolation technique, and would suit strict regulatory segregation where co-tenancy is prohibited outright.

  • ✓

    Use a virtual firewall to create per-VM security groups

    Why this is correct

    A virtual firewall enforcing per-VM security groups provides microsegmentation at the hypervisor layer, filtering east-west traffic between VMs regardless of subnet. This directly satisfies the requirement that different customers' VMs cannot communicate unless explicitly permitted, since policy is applied per virtual machine rather than relying on physical network boundaries.

  • ✗

    Enable hypervisor memory overcommitment

    Why it's wrong here

    Memory overcommitment governs how guest RAM is allocated against host physical memory; it has no bearing on inter-VM network isolation. It is tempting as a hypervisor-level tuning option, and would be relevant when consolidating VMs to raise density, not for enforcing tenant traffic separation.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.