A cloud provider uses KVM as its hypervisor. To prevent a malicious VM from reading memory allocated to another VM, which hardware-assisted memory isolation technology should be enabled?
Trap 1: IOMMU (Input-Output Memory Management Unit)
Incorrect. IOMMU provides isolation for device-initiated DMA accesses, not for CPU memory accesses between virtual machines. It does prevent devices from reading arbitrary VM memory but does not protect against a VM reading another VM's memory via CPU instructions.
Trap 2: Intel TXT (Trusted Execution Technology)
Intel TXT establishes a measured launch environment and verifies platform integrity; it does not isolate per-VM memory. KVM needs Intel VT-d or AMD-Vi (IOMMU) with second-level address translation so each guest's memory is mapped separately. TXT would be chosen for attestation of the hypervisor boot chain.
Trap 3: Intel SGX (Software Guard Extensions)
Intel SGX isolates memory within a single process's enclave, protecting code and data from the host and other processes on that same VM; it does not partition memory between separate guest VMs. Cross-VM isolation on KVM relies on Intel VT-d or AMD-Vi with an IOMMU for DMA remapping. SGX would be correct for shielding secrets inside one workload.
- A
IOMMU (Input-Output Memory Management Unit)
Why it fails: Incorrect. IOMMU provides isolation for device-initiated DMA accesses, not for CPU memory accesses between virtual machines. It does prevent devices from reading arbitrary VM memory but does not protect against a VM reading another VM's memory via CPU instructions.
- B
Intel TXT (Trusted Execution Technology)
Why it fails: Intel TXT establishes a measured launch environment and verifies platform integrity; it does not isolate per-VM memory. KVM needs Intel VT-d or AMD-Vi (IOMMU) with second-level address translation so each guest's memory is mapped separately. TXT would be chosen for attestation of the hypervisor boot chain.
- C
Intel SGX (Software Guard Extensions)
Why it fails: Intel SGX isolates memory within a single process's enclave, protecting code and data from the host and other processes on that same VM; it does not partition memory between separate guest VMs. Cross-VM isolation on KVM relies on Intel VT-d or AMD-Vi with an IOMMU for DMA remapping. SGX would be correct for shielding secrets inside one workload.
- D
AMD SEV (Secure Encrypted Virtualization)
Correct. AMD Secure Encrypted Virtualization (SEV) encrypts the memory of each VM using a unique key, so even if a malicious VM attempts to read memory allocated to another VM, it will only see encrypted data, thus providing hardware-assisted memory isolation.