SSCP Systems and Application Security Practice Question
A company uses multiple virtual machines on a single hypervisor. To prevent a VM from escaping its virtualized environment and compromising the hypervisor, which of the following should be implemented?
⚠ Common exam trap
Watch out — candidates often confuse network segmentation or host-based firewalls with hypervisor-level security; candidates often pick option A or C because they think isolating management traffic or adding a firewall prevents escape, but the question specifically asks about preventing a VM from escaping its virtualized environment, which requires securing the hypervisor and guest tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply hypervisor security patches and disable unnecessary VM guest tools
VM escape attacks typically exploit vulnerabilities in the hypervisor itself or in the guest tools (like VMware Tools or VirtualBox Guest Additions) that run with elevated privileges. Applying hypervisor security patches closes known vulnerabilities that could allow a VM to break out, while disabling unnecessary guest tools reduces the attack surface that an attacker could leverage to interact with the hypervisor. Together, these measures directly harden the virtualization layer against escape attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a separate network for VM management traffic
Why it's wrong here
Separating management traffic onto its own network segments administrative access; it does nothing to stop a guest VM exploiting the hypervisor. It is tempting because network isolation correctly limits lateral movement between workloads, but VM escape is contained through hypervisor hardening and isolation controls.
- ✓
Apply hypervisor security patches and disable unnecessary VM guest tools
Why this is correct
Patching the hypervisor closes known privilege-escalation vulnerabilities that permit VM escape, while removing unnecessary guest tools shrinks the guest-to-host attack surface, such as shared folders and clipboard channels. Together these directly satisfy the stem's requirement to stop a VM compromising the hypervisor.
- ✗
Deploy a host-based firewall on each VM
Why it's wrong here
A host-based firewall filters network traffic inside the guest, but VM escape exploits hypervisor or virtualisation bugs, not network paths, so filtering packets cannot stop it. Host-based firewalls suit controlling inbound and outbound traffic per instance, not hypervisor isolation.
- ✗
Enable VM snapshots to restore in case of compromise
Why it's wrong here
Snapshots capture point-in-time disk state for recovery; they do not constrain a guest's access to hypervisor interfaces, so an escape exploit still succeeds. Snapshots are the right choice for rollback after corruption or a failed patch, not for isolating VMs from the hypervisor.
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is deploying virtual machines (VMs) in a private cloud environment. To prevent VM escape attacks, which of the following is the most critical security control?
medium- A.Using a separate management network for the hypervisor
- ✓ B.Regularly patching the hypervisor software
- C.Disabling unnecessary VM guest tools
- D.Implementing a host-based firewall on each VM
Why B: Regularly patching the hypervisor software is the most critical control to prevent VM escape attacks because these attacks typically exploit vulnerabilities in the hypervisor itself. Keeping the hypervisor up to date ensures that known security flaws are remediated, reducing the attack surface. While other controls add defense in depth, patching directly addresses the root cause of most escape vulnerabilities.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.