nerdexam
CompTIA

PT0-002 · Question #300

A company requires that all hypervisors have the latest available patches installed. Which of the following would BEST explain the reason why this policy is in place?

The correct answer is B. To reduce the probability of a VM escape attack. A VM escape attack is a critical vulnerability where malicious code running inside a virtual machine exploits a flaw in the hypervisor to break out of the isolated VM environment and gain access to the host OS or other VMs. Keeping the hypervisor fully patched closes known…

Attacks and Exploits

Question

A company requires that all hypervisors have the latest available patches installed. Which of the following would BEST explain the reason why this policy is in place?

Options

  • ATo provide protection against host OS vulnerabilities
  • BTo reduce the probability of a VM escape attack
  • CTo fix any misconfigurations of the hypervisor
  • DTo enable all features of the hypervisor

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    89% (39)
  • C
    7% (3)
  • D
    2% (1)

Explanation

A VM escape attack is a critical vulnerability where malicious code running inside a virtual machine exploits a flaw in the hypervisor to break out of the isolated VM environment and gain access to the host OS or other VMs. Keeping the hypervisor fully patched closes known vulnerabilities that attackers could exploit to achieve this escape. Option A is incorrect because host OS vulnerabilities are addressed by patching the host OS, not the hypervisor. Option C (misconfigurations) is addressed through hardening, not patching. Option D (enabling features) is a benefit but not a security reason for mandatory patch policies.

Topics

#Hypervisor security#Patch management#VM escape#Virtualization security

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice