CISA Protection of Information Assets Practice Question
An IS auditor is assessing the security of an organization's virtualized environment. The organization uses a type 1 hypervisor and has multiple virtual machines (VMs) running on a single physical host. The auditor is concerned about the risk of VM escape, where an attacker compromises the hypervisor from within a VM. Which of the following controls are MOST effective in mitigating this risk? (Choose two.)
⚠ Common exam trap
The trap here is selecting controls that detect or recover from an attack, such as HIDS or backups, instead of preventive controls that directly reduce the likelihood of VM escape.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensuring the hypervisor is kept up to date with the latest security patches.
The most effective controls to mitigate VM escape are patching the hypervisor and hardening VM configurations by disabling unnecessary virtual hardware and shared folders. Patching addresses known vulnerabilities that could be exploited for escape, while reducing the attack surface limits the vectors an attacker can use. Together, these preventive measures significantly reduce the risk of a VM compromising the hypervisor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensuring the hypervisor is kept up to date with the latest security patches.
Why this is correct
Keeping the hypervisor patched is critical because VM escape vulnerabilities are often due to bugs in the hypervisor code. Patches address known exploits that could allow an attacker to break out of a VM and compromise the host. This is a fundamental security practice for any software, and especially for the hypervisor, which is the foundation of the virtualized environment. Regular patching reduces the attack surface and mitigates known escape techniques.
- ✗
Using a host-based intrusion detection system (HIDS) on each VM.
Why it's wrong here
A HIDS on each VM can detect malicious activity within the guest OS, but it does not directly prevent VM escape. If an attacker escapes the VM, they are operating at the hypervisor level, where the HIDS in the VM may not have visibility or control. HIDS is useful for detecting compromises, but it is not a primary mitigation for VM escape. The most effective controls target the hypervisor and the isolation between VMs.
- ✗
Regularly backing up VM images to a separate storage system.
Why it's wrong here
Backups are important for recovery, but they do not prevent VM escape. If an attacker escapes a VM, they could potentially access the hypervisor and other VMs, and backups would not stop that. Backups are a reactive control for data loss, not a preventive control for hypervisor compromise. While having backups is good practice, it is not an effective mitigation for the specific risk of VM escape.
- ✗
Enabling promiscuous mode on the virtual switch to monitor all traffic.
Why it's wrong here
Promiscuous mode on a virtual switch allows a VM to see all traffic on that switch, which can be a security risk because it could allow a compromised VM to sniff traffic from other VMs. It does not mitigate VM escape; in fact, it could aid an attacker in gathering information. Promiscuous mode is typically used for monitoring or IDS, but it should be used cautiously and not as a security control for VM escape.
- ✓
Implementing strict isolation between VMs by disabling unnecessary virtual hardware and shared folders.
Why this is correct
Reducing the attack surface by disabling unnecessary virtual hardware and shared folders limits the channels an attacker can use to interact with the hypervisor. Shared folders and clipboard sharing can be vectors for VM escape or data leakage. By minimizing these features, the auditor reduces the opportunities for an attacker to exploit hypervisor vulnerabilities. This is a preventive control that complements patching by hardening the VM configuration.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.