SY0-701 exam dumps

SY0-701 practice question 169 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 169

Single answerVirtualization

A company hosts several internet-facing applications on a virtualization cluster. During a security review, the administrator discovers that one virtual machine (VM) used for software testing has direct access to the hypervisor management interface and can communicate freely with production VMs on the same host. Management wants to reduce the risk that a compromise of the test VM could affect other VMs or the hypervisor, while keeping the production services online. Which action would BEST address this risk?

  1. A

    Move the test VM to a separate virtual network or host segment and restrict access to the hypervisor management interface to dedicated administrative systems

  2. B

    Increase the CPU and memory assigned to the test VM so it cannot interfere with other workloads on the host

  3. C

    Install host-based antivirus inside each production VM and leave the current virtual networking design unchanged

  4. D

    Convert the test VM into a container so it shares the host OS rather than using the hypervisor

Show answer and explanation

Correct answer: A

Explanation

The best answer is to strengthen isolation within the virtualized environment by separating less-trusted workloads from production systems and protecting the hypervisor management plane. In Security+ terms, virtualization security relies heavily on segmentation, least privilege, and management interface hardening. Industry best practices from major virtualization vendors and security guidance commonly recommend using dedicated management networks, limiting administrative access, and isolating development or testing systems from production workloads. This reduces the chance that a compromise in one guest can be used for VM-to-VM attacks or to target the hypervisor. Resource increases and endpoint tools may help availability or detection, but they do not correct the architectural weakness described in the scenario.

  • A. Correct.

    Correct. Segmentation is a primary security control in virtualized environments. Placing the test VM on a separate virtual network, VLAN, or even a separate host cluster reduces the blast radius if that VM is compromised. Restricting hypervisor management access to dedicated administrative systems or a management network follows best practices by limiting exposure of the management plane. This directly addresses both lateral movement between VMs and unauthorized access to the hypervisor.

  • B. Incorrect.

    Incorrect. Increasing CPU or memory affects performance, not security isolation. A compromised VM with more resources could still attempt lateral movement or attack the hypervisor management interface. This option reflects the misconception that resource contention is the main virtualization security issue in the scenario, when the real problem is insufficient isolation and exposed management access.

  • C. Incorrect.

    Incorrect. Host-based antivirus can help detect malware inside production VMs, but it does not solve the core design issue: the test VM can reach both the hypervisor management interface and production VMs. Antivirus is a useful defense-in-depth measure, but leaving the current network and management exposure unchanged would still permit lateral movement and possible attacks against the virtualization layer.

  • D. Incorrect.

    Incorrect. Converting the test workload to a container would not inherently improve isolation in this scenario. In many cases, containers provide less isolation than full VMs because they share the host OS kernel. This could increase risk rather than reduce it, especially for untrusted or test workloads. The issue is improper segmentation and management-plane exposure, not the mere presence of a VM.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam