exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 420 discussion

Actual exam question from ISC's CISSP
Question #: 420
Topic #: 1
[All CISSP Questions]

How is protection for hypervisor host and software administration functions BEST achieved?

  • A. Enforce network controls using a host-based firewall.
  • B. Deploy the management interface in a dedicated virtual network segment.
  • C. The management traffic pathway should have separate physical network interface cards (NIC) and network.
  • D. Deny permissions to specific virtual machines (VM) groups and objects.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 2 years, 1 month ago
Selected Answer: C
The management traffic pathway should have separate physical network interface cards (NIC) and network
upvoted 5 times
1 year, 10 months ago
C is correct
upvoted 1 times
Most Recent 7 months, 2 weeks ago
Selected Answer: C
I go with C. ChatGPT said first, that B is the correct answer, but at the point I gave him HappyDay030303 answer he reassesed the answer and said I should go with C. ThX HappyDay030303
upvoted 1 times
1 year ago
Selected Answer: C
The question ask for BEST, the best among B and C. If it ask most easiest to deploy or cost effective than it would be B.
upvoted 1 times
1 year, 1 month ago
Selected Answer: B
In practice, you almost never find an independent network interface just for management of the hypervisor management traffic in a physical server. You usually send that traffic in a separate VLAN
upvoted 2 times
1 year, 3 months ago
C. The management traffic pathway should have separate physical network interface cards (NIC) and network. In specific virtualization and hypervisor security contexts, the use of separate physical network interface cards (pNICs) and network connections for the management traffic pathway can provide an additional layer of isolation and security.
upvoted 1 times
1 year, 4 months ago
Selected Answer: C
C: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-125b.pdf Isolation of the hypervisor’s management network using virtual switches needs special configuration. In addition to dedicated virtual switches, the management traffic pathway should have separate pNICs and separate physical network connections
upvoted 4 times
7 months, 2 weeks ago
I go with C. Thank you for pointing the NIST paper and the explanation out.
upvoted 1 times
1 year, 4 months ago
C) The management traffic pathway should have separate physical network interface cards (NICs) and network. The best way to protect hypervisor host administration functions is to physically separate management traffic from production traffic. This is achieved by using dedicated NICs and networks for management connections to the hypervisor. A) Host firewalls help but do not provide physical separation. B) Virtual network segmentation only provides logical separation. D) VM permissions only control individual VMs, not overall hypervisor access. By assigning hypervisor/host management to distinct NICs and networks, the management pathway is isolated from production VM traffic. This physical air gap limits attack surface and access from production workloads to the privileged hypervisor administration plane. It provides strong protection aligned to the principle of least privilege.
upvoted 1 times
1 year, 6 months ago
Selected Answer: B
B. Deploy the management interface in a dedicated virtual network segment. The best way to achieve protection for hypervisor host and software administration functions is by deploying the management interface in a dedicated virtual network segment. This practice isolates the management traffic from other network traffic, reducing the attack surface and improving security. This dedicated network segment should be appropriately segmented and isolated from other segments to prevent unauthorized access and potential attacks on the hypervisor host and management functions.
upvoted 1 times
1 year, 11 months ago
Selected Answer: C
Option C is correct
upvoted 1 times
1 year, 11 months ago
Selected Answer: B
Option C is great but might be more expensive, so best answer is option B
upvoted 2 times
2 years ago
Selected Answer: C
C - The management traffic pathway should have separate physical network interface cards (NIC) and network.
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago