GSEC Virtualization, Cloud, and AI Essentials Practice Question
A healthcare company runs a three-tier application on VMware ESXi hosts. An auditor discovers that vMotion traffic between hosts is transmitted over the same physical switch as guest virtual machine data traffic. The security team must ensure that live migration traffic cannot be sniffed or tampered with by a compromised guest VM on the same network segment. Which action best addresses this finding?
⚠ Common exam trap
The trap here is assuming that enabling promiscuous mode or an IP-based ACL improves visibility or control, when it actually broadens exposure and never protects the vMotion stream.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a dedicated vMotion VMkernel port group on an isolated VLAN and enable encryption for vMotion.
Live migration traffic carries complete guest memory contents, so it must be both isolated and protected. Placing vMotion on a dedicated VMkernel port group in an isolated VLAN removes it from the guest data path, and enabling vMotion encryption ensures that even a compromised guest or a tapped uplink cannot read or alter the migration stream. Together these controls directly remediate the auditor's concern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a Layer 2 ACL on the physical switch to permit only ESXi management IP addresses on the guest VLAN.
Why it's wrong here
A Layer 2 ACL restricting traffic by management IP does not separate vMotion from guest data, because vMotion uses its own VMkernel interface and IP. The ACL would not prevent a compromised guest on the same segment from observing migration frames, nor does it provide encryption. This control addresses management access, not the confidentiality or integrity of live migration traffic.
- ✓
Configure a dedicated vMotion VMkernel port group on an isolated VLAN and enable encryption for vMotion.
Why this is correct
A dedicated vMotion VMkernel interface placed on a separate VLAN segments migration traffic away from guest data paths, and vMotion encryption protects the transferred memory contents even if the underlying network is observed. This directly mitigates both sniffing and tampering by a compromised guest because the migration stream never shares the guest-facing segment and is cryptographically protected.
- ✗
Move all virtual machines to a single ESXi host so that vMotion is never used.
Why it's wrong here
Consolidating all workloads onto one host eliminates vMotion but destroys the availability and maintenance benefits of the cluster and creates a single point of failure. It does not address the underlying security architecture and is operationally unacceptable for a production three-tier application. The requirement is to secure migration traffic, not to abandon live migration entirely.
- ✗
Enable promiscuous mode on the vSwitch so that vMotion frames can be inspected by the host firewall.
Why it's wrong here
Promiscuous mode allows virtual network adapters to receive frames not addressed to them, which would actually worsen the exposure by permitting guests to observe more traffic. It provides no cryptographic protection for vMotion and does not isolate migration traffic from guest data. The host firewall does not inspect vMotion frames in this manner, so this setting fails to remediate the auditor's finding.
Visual reference
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.