CAS-001 · Question #286
The Chief Technology Officer (CTO) has decided that servers in the company datacenter should be virtualized to conserve physical space. The risk assurance officer is concerned that the project team…
The correct answer is C. A weakly protected guest OS combined with a host OS exploit increases the chance of a successful. The core risk of co-mingling VMs with varying security requirements is VM escape: a weakly configured or compromised guest OS lowers the bar for an attacker to exploit a vulnerability in the host OS or hypervisor, potentially breaking out of the VM sandbox and gaining access to…
Question
The Chief Technology Officer (CTO) has decided that servers in the company datacenter should be virtualized to conserve physical space. The risk assurance officer is concerned that the project team in charge of virtualizing servers plans to co-mingle many guest operating systems with different security requirements to speed up the rollout and reduce the number of host operating systems or hypervisors required. Which of the following BEST describes the risk assurance officer's concerns?
Options
- ACo-mingling guest operating system with different security requirements allows guest OS privilege
- BCo-mingling of guest operating systems with different security requirements increases the risk of data
- CA weakly protected guest OS combined with a host OS exploit increases the chance of a successful
- DA weakly protected host OS will allow the hypervisor to become corrupted resulting in data throughput
How the community answered
(19 responses)- A26% (5)
- B11% (2)
- C53% (10)
- D11% (2)
Explanation
The core risk of co-mingling VMs with varying security requirements is VM escape: a weakly configured or compromised guest OS lowers the bar for an attacker to exploit a vulnerability in the host OS or hypervisor, potentially breaking out of the VM sandbox and gaining access to the host and all other guest VMs on that system. Option C precisely describes this attack chain. Option A mentions guest OS privilege escalation, which is less specific. Option B addresses data leakage between VMs, which is a valid concern but not the primary VM security risk described. Option D incorrectly focuses on host OS protecting the hypervisor from corruption rather than the VM escape scenario.
Topics
Community Discussion
No community discussion yet for this question.