Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is assessing the security of an organization's virtualization environment. The auditor finds that the hypervisor management interface is accessible from the general corporate network and uses default credentials. Which of the following is the MOST critical risk associated with this finding?

⚠ Common exam trap

The trap here is focusing on specific technical attacks like VM escape or traffic sniffing while underestimating the immediate and severe impact of unauthorized administrative access to the hypervisor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An attacker could gain control of the hypervisor and compromise all hosted virtual machines.

The most critical risk is that an attacker could gain control of the hypervisor and compromise all hosted virtual machines. The hypervisor management interface is a privileged access point; if exposed and using default credentials, it can be easily exploited. An attacker with administrative control can manipulate all VMs, access sensitive data, and disrupt services across the entire virtual infrastructure. This represents a single point of failure with catastrophic potential.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An attacker could cause a denial of service by overwhelming the hypervisor with management requests.

    Why it's wrong here

    A denial of service is possible, but it is a lesser risk compared to complete compromise. With default credentials, an attacker can not only cause a DoS but also steal data, alter configurations, and maintain persistent access. The most critical risk is the loss of confidentiality, integrity, and availability of all virtual machines, which is enabled by unauthorized administrative access. DoS is just one of many potential impacts.

  • ✗

    An attacker could exploit a vulnerability in the hypervisor to escape to the host operating system.

    Why it's wrong here

    Hypervisor escape vulnerabilities are serious, but they require a specific exploit and are not guaranteed. In contrast, default credentials on an exposed management interface provide immediate, authorized access without needing an exploit. The risk of full control via legitimate credentials is more immediate and certain than the potential for a hypervisor escape, which is a more complex attack vector.

  • ✓

    An attacker could gain control of the hypervisor and compromise all hosted virtual machines.

    Why this is correct

    The hypervisor management interface is a high-value target because it controls the entire virtual infrastructure. If an attacker accesses it with default credentials, they can potentially shut down, modify, or create virtual machines, and even move laterally to other systems. This could lead to a complete compromise of all hosted workloads, data breaches, and service outages. This is the most critical risk because it affects the entire virtual environment, not just a single VM.

  • ✗

    An attacker could intercept network traffic between virtual machines on the same host.

    Why it's wrong here

    While traffic interception between VMs is a potential risk in virtualized environments, it typically requires access to the virtual switch or hypervisor. However, the scenario specifically highlights the management interface being exposed with default credentials, which directly grants administrative control. The ability to intercept traffic is a secondary concern compared to full hypervisor compromise, which can enable various attacks including traffic interception.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.