nerdexam
CompTIA

CAS-002 · Question #47

A company has a legacy virtual cluster which was added to the datacenter after a small company was acquired. All VMs on the cluster use the same virtual network interface to connect to the corporate…

The correct answer is A. Visibility on the traffic between the virtual machines can impact confidentiality. When multiple VMs with different data sensitivity levels (customer data, financial data, public web servers) all share the same virtual network interface and virtual switch, traffic between VMs traverses the same shared virtual network segment. This means a compromised or…

Technical Integration of Enterprise Components

Question

A company has a legacy virtual cluster which was added to the datacenter after a small company was acquired. All VMs on the cluster use the same virtual network interface to connect to the corporate data center LAN. Some of the virtual machines on the cluster process customer data, some process company financial data, and others act as externally facing web servers. Which of the following security risks can result from the configuration in this scenario?

Options

  • AVisibility on the traffic between the virtual machines can impact confidentiality
  • BNIC utilization can exceed 50 percent and impact availability
  • CShared virtual switches can negatively impact the integrity of network packets
  • DAdditional overhead from network bridging can affect availability

How the community answered

(28 responses)
  • A
    79% (22)
  • B
    4% (1)
  • C
    11% (3)
  • D
    7% (2)

Explanation

When multiple VMs with different data sensitivity levels (customer data, financial data, public web servers) all share the same virtual network interface and virtual switch, traffic between VMs traverses the same shared virtual network segment. This means a compromised or malicious VM could potentially sniff or intercept traffic from other VMs on the same virtual switch - a direct confidentiality risk. This is analogous to having all servers on a flat, unsegmented physical LAN. Options B and D relate to availability/performance, not the primary security concern of mixing data classifications on a shared network. Option C is incorrect because virtual switches do not inherently corrupt packet integrity; the concern is unauthorized visibility, not data modification.

Topics

#virtualization#virtual networking#traffic confidentiality#VM security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice