SY0-701 exam dumps

SY0-701 practice question 94 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 94

Single answerVirtualization: Virtual machine (VM) escape , Resource reuse

A company runs a multi-tenant private cloud for several internal business units. After a penetration test, the security team discovers two serious issues: a tester was able to use a hypervisor vulnerability from inside one VM to interact with the host, and another tester recovered fragments of a previous tenant's data from a newly provisioned virtual disk. The company wants the most effective control that addresses both findings across the environment. Which of the following should the security architect implement first?

  1. A

    Establish a hardened VM decommissioning and provisioning process that sanitizes reusable storage and memory resources, and aggressively patch and harden the hypervisor and management plane

  2. B

    Disable snapshots on all VMs and require administrators to use jump boxes for console access

  3. C

    Increase the RAM and CPU allocation for each VM so tenants are less likely to share physical resources

  4. D

    Move all workloads into a single large VM on each host to reduce the number of guest operating systems

Show answer and explanation

Correct answer: A

Explanation

This question combines two Security+ virtualization concerns: VM escape and resource reuse. VM escape occurs when code running in a guest VM breaks isolation and interacts with the hypervisor or host, so the primary defenses are hypervisor patching, minimizing exposed services, hardening the host, restricting management access, and following vendor security advisories. Resource reuse refers to residual data exposure when storage, memory, or other shared resources are reassigned without proper sanitization. In practice, organizations should use secure deprovisioning processes, sanitize or cryptographically erase virtual disks before reuse, and ensure templates and snapshots do not expose prior tenant data. These practices align with common guidance from NIST on media sanitization and virtualization security, such as NIST SP 800-88 for sanitization concepts and NIST SP 800-125 for security recommendations in virtualized environments.

  • A. Correct.

    Correct. The scenario describes two separate virtualization risks: VM escape and resource reuse. VM escape is mitigated primarily by reducing hypervisor attack surface, hardening the host and management interfaces, and promptly applying vendor patches for the hypervisor and virtualization tools. Resource reuse is mitigated by sanitizing storage and other reusable resources before reassignment so a new tenant cannot recover residual data. A formal decommissioning/provisioning process with secure wiping or cryptographic erasure where supported directly addresses the residual-data issue, while hypervisor hardening and patching addresses the escape path.

  • B. Incorrect.

    Incorrect. Disabling snapshots may reduce some operational and forensic risks, and jump boxes can improve administrative access control, but neither control directly remediates residual tenant data on reused virtual disks. They also do not address the root cause of a VM escape through a hypervisor vulnerability. This option reflects a common misconception that administrative access controls alone solve virtualization isolation failures.

  • C. Incorrect.

    Incorrect. Adding more CPU and RAM can improve performance, but it does not prevent a guest from exploiting a hypervisor flaw, nor does it sanitize residual data from storage or memory resources before reuse. This is a plausible distractor because people often associate 'resource sharing' with capacity planning, but resource reuse in security refers to leftover data exposure after reassignment, not just contention.

  • D. Incorrect.

    Incorrect. Consolidating workloads into one large VM would reduce segmentation and increase blast radius. It would not fix a vulnerable hypervisor, and it would create additional operational and security risks by combining unrelated workloads. It also does nothing to ensure virtual disks or other resources are sanitized before being reused by another tenant.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam