Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: In a virtualized environment, which security…

In a virtualized environment, which security control is most effective for isolating VMs from each other?

⚠ Common exam trap

Many candidates confuse VLAN segmentation (Option C) as the primary isolation mechanism, but in a virtualized environment, VLANs are configured at the hypervisor level as part of virtual switch policies, making 'Hypervisor-level network policies' the more precise and encompassing answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Hypervisor-level network policies

Hypervisor-level network policies, such as virtual switches with port groups and VLAN tagging, enforce isolation directly at the hypervisor layer, ensuring that VM traffic is segmented without relying on guest OS configurations. This control is independent of the VM's own firewall settings and can prevent lateral movement even if a VM is compromised, because the hypervisor mediates all network I/O.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Host-based firewall on each VM

    Why it's wrong here

    A host-based firewall operates within the guest operating system of a virtual machine. While it provides some protection for that specific VM, it can be easily bypassed or disabled if the underlying hypervisor is compromised. Therefore, it does not offer robust isolation against threats originating from or controlling the virtualization layer itself, making it an insufficient primary control in a multi-tenant or high-security virtualized environment.

  • Physical separation

    Why it's wrong here

    Physical separation entails dedicating distinct hardware for each workload, effectively eliminating the core benefits of virtualization such as resource consolidation, flexibility, and cost efficiency. While it offers strong isolation by design, it fundamentally defeats the purpose of deploying a virtualized environment. This approach negates the very advantages virtualization seeks to provide, rendering it an impractical and counterproductive security control in this context.

  • Virtual LAN (VLAN) segmentation

    Why it's wrong here

    Virtual LAN (VLAN) segmentation provides network isolation by logically separating traffic at Layer 2, preventing direct communication between different VLANs. However, it does not offer full isolation within a virtualized environment, as VMs within the same VLAN can still communicate and potentially impact each other. Furthermore, VLANs do not protect against hypervisor-level attacks or provide compute resource isolation, making them insufficient for comprehensive security in a shared virtual infrastructure.

  • Hypervisor-level network policies

    Why this is correct

    Hypervisor-level network policies are enforced directly by the hypervisor, which sits above all virtual machines and has ultimate control over their network interactions. This allows for granular control over traffic flow, micro-segmentation, and robust isolation between VMs, even those on the same virtual network. Because these policies are enforced at a layer inaccessible to guest operating systems, they provide the most effective and resilient security control against compromised VMs or lateral movement within the virtualized environment.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.