Courseiva
Systems and Application SecuritymediumMultiple ChoiceObjective-mapped

SSCP Systems and Application Security Practice Question

A company uses multiple virtual machines on a single hypervisor. To prevent a VM from escaping its virtualized environment and compromising the hypervisor, which of the following should be implemented?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Apply hypervisor security patches and disable unnecessary VM guest tools

VM escape attacks exploit vulnerabilities in the hypervisor. Keeping the hypervisor patched and disabling unnecessary VM guest tools reduces attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use a separate network for VM management traffic

    Why it's wrong here

    This is good practice but primarily protects management interfaces, not directly VM escape.

  • Apply hypervisor security patches and disable unnecessary VM guest tools

    Why this is correct

    Patching hypervisor and minimizing guest tools reduce the risk of VM escape.

  • Deploy a host-based firewall on each VM

    Why it's wrong here

    Host-based firewalls protect VMs from network attacks but do not prevent VM escape.

  • Enable VM snapshots to restore in case of compromise

    Why it's wrong here

    Snapshots help recovery but do not prevent escape; they may also reintroduce vulnerabilities.

About these practice questions

This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is deploying virtual machines (VMs) in a private cloud environment. To prevent VM escape attacks, which of the following is the most critical security control?

medium
  • A.Using a separate management network for the hypervisor
  • B.Regularly patching the hypervisor software
  • C.Disabling unnecessary VM guest tools
  • D.Implementing a host-based firewall on each VM

Why B: VM escape attacks exploit vulnerabilities in the hypervisor to break out of a VM. Keeping the hypervisor patched is the primary defense against known vulnerabilities.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.