nerdexam
Isaca

CISA · Question #194

When auditing a virtual IT system, it is MOST important to verify the security of which of the following?

The correct answer is C. Hypervisor. The hypervisor is the most critical component to secure in a virtual environment because it sits beneath all virtual machines and controls access to physical hardware - a compromised hypervisor means every VM running on it is compromised, regardless of their individual security p

Submitted by ashley.k· Apr 18, 2026Protection of Information Assets

Question

When auditing a virtual IT system, it is MOST important to verify the security of which of the following?

Options

  • AVirtual machines (VMs)
  • BWorkloads
  • CHypervisor
  • DManagement console

How the community answered

(24 responses)
  • C
    96% (23)
  • D
    4% (1)

Explanation

The hypervisor is the most critical component to secure in a virtual environment because it sits beneath all virtual machines and controls access to physical hardware - a compromised hypervisor means every VM running on it is compromised, regardless of their individual security posture. Virtual machines (A) are important to secure, but their security ultimately depends on the integrity of the hypervisor beneath them. Workloads (B) are applications running inside VMs, making them too high in the stack to be the most foundational concern. The management console (D) is a high-value target but is typically an application-layer interface; if the hypervisor itself is compromised, console-level controls become meaningless.

Memory tip: Think of the hypervisor as the "foundation of the house" - you can have strong locks on every room (VMs), but if the foundation is cracked, the whole structure is unsafe. Own the hypervisor, own everything.

Topics

#Virtualization security#Hypervisor security#IT audit#Critical infrastructure

Community Discussion

No community discussion yet for this question.

Full CISA Practice