hardMultiple ChoiceObjective-mapped
CISSP Practice Question: In a virtualized environment, which security…
In a virtualized environment, which security control is most effective for isolating VMs from each other?
⚠ Common exam trap
Many candidates confuse VLAN segmentation (Option C) as the primary isolation mechanism, but in a virtualized environment, VLANs are configured at the hypervisor level as part of virtual switch policies, making 'Hypervisor-level network policies' the more precise and encompassing answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hypervisor-level network policies
Hypervisor-level network policies, such as virtual switches with port groups and VLAN tagging, enforce isolation directly at the hypervisor layer, ensuring that VM traffic is segmented without relying on guest OS configurations. This control is independent of the VM's own firewall settings and can prevent lateral movement even if a VM is compromised, because the hypervisor mediates all network I/O.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Host-based firewall on each VM
Why it's wrong here
A host-based firewall operates within the guest operating system of a virtual machine. While it provides some protection for that specific VM, it can be easily bypassed or disabled if the underlying hypervisor is compromised. Therefore, it does not offer robust isolation against threats originating from or controlling the virtualization layer itself, making it an insufficient primary control in a multi-tenant or high-security virtualized environment.
- ✗
Physical separation
Why it's wrong here
Physical separation entails dedicating distinct hardware for each workload, effectively eliminating the core benefits of virtualization such as resource consolidation, flexibility, and cost efficiency. While it offers strong isolation by design, it fundamentally defeats the purpose of deploying a virtualized environment. This approach negates the very advantages virtualization seeks to provide, rendering it an impractical and counterproductive security control in this context.
- ✗
Virtual LAN (VLAN) segmentation
Why it's wrong here
Virtual LAN (VLAN) segmentation provides network isolation by logically separating traffic at Layer 2, preventing direct communication between different VLANs. However, it does not offer full isolation within a virtualized environment, as VMs within the same VLAN can still communicate and potentially impact each other. Furthermore, VLANs do not protect against hypervisor-level attacks or provide compute resource isolation, making them insufficient for comprehensive security in a shared virtual infrastructure.
- ✓
Hypervisor-level network policies
Why this is correct
Hypervisor-level network policies are enforced directly by the hypervisor, which sits above all virtual machines and has ultimate control over their network interactions. This allows for granular control over traffic flow, micro-segmentation, and robust isolation between VMs, even those on the same virtual network. Because these policies are enforced at a layer inaccessible to guest operating systems, they provide the most effective and resilient security control against compromised VMs or lateral movement within the virtualized environment.
Visual reference
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security control
A security control is a safeguard or countermeasure designed to protect the confidentiality, integrity, and availability of information systems and data.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.