GSEC Virtualization, Cloud, and AI Essentials Practice Question
An organization is migrating to a hybrid cloud environment. Which security control is most effective for preventing unauthorized lateral movement between virtual machines residing on the same physical hypervisor?
⚠ Common exam trap
Candidates often suggest traditional perimeter firewalls or VLANs. They fail to realize that traffic between VMs on the same host often bypasses physical network hardware, necessitating host-level micro-segmentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Utilizing micro-segmentation policies via distributed firewalls.
Micro-segmentation is critical in virtualized environments because traditional network perimeter defenses cannot see traffic moving between VMs on the same host. By applying host-based or hypervisor-level firewalls, security teams restrict traffic based on identity and function rather than IP address. This mitigates the risk of a compromised workload pivoting to sensitive internal assets within the shared virtual infrastructure, which is a key security requirement for modern cloud architectures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploying a Network Intrusion Detection System (NIDS) at the virtual switch level.
Why it's wrong here
NIDS solutions are primarily visibility tools that monitor traffic rather than enforcing granular access controls. While useful for logging and alerting on suspicious activity, they do not inherently prevent lateral movement between virtual machines, as they lack the blocking capabilities required for active security enforcement.
- ✗
Implementing a traditional hardware-based firewall at the edge of the datacenter.
Why it's wrong here
Edge firewalls protect the perimeter but are completely invisible to East-West traffic occurring within the hypervisor layer. Since traffic between virtual machines on the same host never leaves the physical switch fabric, the edge device cannot inspect or block such communication flows effectively.
- ✓
Utilizing micro-segmentation policies via distributed firewalls.
Why this is correct
Distributed firewalls operate at the virtual NIC level, enabling granular security policies that follow the VM regardless of host migration. This effectively isolates workloads from each other, preventing lateral movement even if the attacker has gained local access, which is fundamental to zero-trust cloud security models.
- ✗
Enforcing full disk encryption on all virtual hard drives.
Why it's wrong here
Full disk encryption protects data at rest in the event of physical storage theft or unauthorized access to the virtual disk file. It provides no protection against network-based lateral movement or unauthorized traffic between active virtual machines, making it irrelevant to this specific security objective.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.