Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 420 discussion

Actual exam question from ISC's CISSP
Question #: 420
Topic #: 1
[All CISSP Questions]

How is protection for hypervisor host and software administration functions BEST achieved?

  • A. Enforce network controls using a host-based firewall.
  • B. Deploy the management interface in a dedicated virtual network segment.
  • C. The management traffic pathway should have separate physical network interface cards (NIC) and network.
  • D. Deny permissions to specific virtual machines (VM) groups and objects.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
zoro3309
Highly Voted 1 year, 9 months ago
Selected Answer: C
The management traffic pathway should have separate physical network interface cards (NIC) and network
upvoted 5 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
1460168
Most Recent 3 months, 2 weeks ago
Selected Answer: C
I go with C. ChatGPT said first, that B is the correct answer, but at the point I gave him HappyDay030303 answer he reassesed the answer and said I should go with C. ThX HappyDay030303
upvoted 1 times
...
hoho2000
8 months, 2 weeks ago
Selected Answer: C
The question ask for BEST, the best among B and C. If it ask most easiest to deploy or cost effective than it would be B.
upvoted 1 times
...
gjimenezf
9 months, 3 weeks ago
Selected Answer: B
In practice, you almost never find an independent network interface just for management of the hypervisor management traffic in a physical server. You usually send that traffic in a separate VLAN
upvoted 2 times
...
Soleandheel
11 months, 1 week ago
C. The management traffic pathway should have separate physical network interface cards (NIC) and network. In specific virtualization and hypervisor security contexts, the use of separate physical network interface cards (pNICs) and network connections for the management traffic pathway can provide an additional layer of isolation and security.
upvoted 1 times
...
HappyDay030303
1 year ago
Selected Answer: C
C: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-125b.pdf Isolation of the hypervisor’s management network using virtual switches needs special configuration. In addition to dedicated virtual switches, the management traffic pathway should have separate pNICs and separate physical network connections
upvoted 3 times
1460168
3 months, 2 weeks ago
I go with C. Thank you for pointing the NIST paper and the explanation out.
upvoted 1 times
...
...
InclusiveSTEAM
1 year, 1 month ago
C) The management traffic pathway should have separate physical network interface cards (NICs) and network. The best way to protect hypervisor host administration functions is to physically separate management traffic from production traffic. This is achieved by using dedicated NICs and networks for management connections to the hypervisor. A) Host firewalls help but do not provide physical separation. B) Virtual network segmentation only provides logical separation. D) VM permissions only control individual VMs, not overall hypervisor access. By assigning hypervisor/host management to distinct NICs and networks, the management pathway is isolated from production VM traffic. This physical air gap limits attack surface and access from production workloads to the privileged hypervisor administration plane. It provides strong protection aligned to the principle of least privilege.
upvoted 1 times
...
BoyBastos
1 year, 2 months ago
Selected Answer: B
B. Deploy the management interface in a dedicated virtual network segment. The best way to achieve protection for hypervisor host and software administration functions is by deploying the management interface in a dedicated virtual network segment. This practice isolates the management traffic from other network traffic, reducing the attack surface and improving security. This dedicated network segment should be appropriately segmented and isolated from other segments to prevent unauthorized access and potential attacks on the hypervisor host and management functions.
upvoted 1 times
...
Goseu
1 year, 7 months ago
Selected Answer: C
Option C is correct
upvoted 1 times
...
invincible96
1 year, 8 months ago
Selected Answer: B
Option C is great but might be more expensive, so best answer is option B
upvoted 2 times
...
sausageman
1 year, 8 months ago
Selected Answer: C
C - The management traffic pathway should have separate physical network interface cards (NIC) and network.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...