CCSP · Question #362
Security best practices in a virtualized network environment would include which of the following? Response:
The correct answer is A. Using distinct ports and port groups for various VLANs on a virtual switch rather than running. Security best practices in a virtualized network environment involve segmenting traffic by using distinct virtual switch ports and port groups for different VLANs. This isolation helps prevent unauthorized access and reduces the attack surface between different network segments…
Question
Security best practices in a virtualized network environment would include which of the following? Response:
Options
- AUsing distinct ports and port groups for various VLANs on a virtual switch rather than running
- BRunning iSCSI traffic unencrypted in order to have it observed and monitored by NIDS
- CAdding HIDS to all virtual guests
- DHardening all outward-facing firewalls in order to make them resistant to attack
How the community answered
(37 responses)- A78% (29)
- B3% (1)
- C14% (5)
- D5% (2)
Why each option
Security best practices in a virtualized network environment involve segmenting traffic by using distinct virtual switch ports and port groups for different VLANs. This isolation helps prevent unauthorized access and reduces the attack surface between different network segments within the virtual environment.
Using distinct ports and port groups for various VLANs on a virtual switch enhances network segmentation and isolation within the virtualized environment. This practice prevents traffic from different security zones or functions from intermingling, thereby improving security and control by applying specific policies to each segment.
Running iSCSI traffic unencrypted is a security risk as it exposes sensitive storage data to eavesdropping, even if monitored by NIDS.
While adding HIDS to virtual guests is a good security practice, the question asks for a network security best practice in a virtualized network environment, and segmentation (Option A) is more fundamental to network architecture.
Hardening outward-facing firewalls is a general security best practice for any network, but it is not specific to the virtualized network environment aspect of the question, which implies practices within the hypervisor and virtual switch layer.
Concept tested: Virtual network segmentation security
Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-62B3FF6E-F1F3-4C10-85A3-9A91D0E0967A.html
Topics
Community Discussion
No community discussion yet for this question.