SY0-701 exam dumps

SY0-701 practice question 170 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 170

Single answerVirtualization

A company hosts several internal applications on virtual machines in a shared VMware environment. A security administrator discovers that a developer created a snapshot of a production VM before testing a software update and then left the snapshot in place for several months. During an audit, the administrator is asked which security risk this situation creates and what concern should be addressed first. Which of the following is the BEST answer?

  1. A

    The snapshot may contain outdated sensitive data and system state that could be restored or accessed, weakening patch and configuration management

  2. B

    The snapshot automatically encrypts the VM state, so the main risk is only increased CPU usage on the hypervisor

  3. C

    The snapshot prevents privilege escalation inside the guest OS, but it increases the chance of hardware failure on the host

  4. D

    The snapshot converts the VM into an immutable image, eliminating malware persistence but complicating backups

Show answer and explanation

Correct answer: A

Explanation

In virtualization, snapshots are useful for short-term rollback but can create security and operational risk if kept longer than necessary. Old snapshots may retain sensitive information and allow a VM to be reverted to an outdated, unpatched, or misconfigured state. This can conflict with vulnerability management, change control, and secure configuration baselines. Security best practices from major virtualization vendors, including VMware administrative guidance, generally recommend limiting snapshot lifetime, restricting access to snapshot files and management functions, and not treating snapshots as a long-term backup method. For Security+ purposes, candidates should recognize that virtualization artifacts such as snapshots, templates, and images must be governed because they can expose data and reintroduce vulnerabilities if not managed properly.

  • A. Correct.

    Correct. VM snapshots capture the system state at a point in time, which can include disk contents, memory state in some cases, and configuration information depending on the platform and snapshot type. If retained too long, they can preserve outdated credentials, unpatched system files, and sensitive data. From a security perspective, an old snapshot can undermine patch management and configuration baselines because the VM could be reverted to a vulnerable state. This is a practical concern in virtualized environments and aligns with standard security guidance to control snapshots and protect stored VM artifacts.

  • B. Incorrect.

    Incorrect. Snapshots do not inherently provide encryption. Their security depends on the storage platform and administrative controls protecting the snapshot files or datastore. While long-lived snapshots can affect storage performance and potentially I/O, saying the main risk is only CPU usage is inaccurate and misses the primary security concern: preservation and possible restoration of vulnerable or sensitive historical VM state.

  • C. Incorrect.

    Incorrect. A snapshot does not prevent privilege escalation within the guest OS. It is primarily a point-in-time record of VM state used for rollback or recovery. Hardware failure risk on the host is not the principal security issue created by leaving a snapshot in place. This option reflects a misunderstanding of what snapshots do and how virtualization security risks are introduced.

  • D. Incorrect.

    Incorrect. A snapshot is not the same as an immutable golden image. It does not eliminate malware persistence; in fact, reverting to a compromised snapshot could reintroduce malware or insecure configurations. Although snapshots can complicate operational tasks such as backup strategy, this option incorrectly describes the security effect of snapshots.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam