ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A public IaaS provider uses KVM to host multitenant workloads. A critical hypervisor privilege-escalation (VM-escape) flaw that abuses direct device passthrough handling has just been disclosed. While vendor patches are still being validated, which immediate action will most directly reduce the likelihood that a malicious tenant can break out of its guest and reach the host or neighboring tenants?
Store every tenant's encryption keys inside the same virtual machine that uses them to avoid network exposure.
Place each tenant in a separate virtual network and enforce restrictive security group rules.
Enable memory page deduplication so identical memory pages are shared across guest VMs.
Disable all PCI, USB, and other device passthrough so guests use only standard virtual devices.
Disabling all forms of PCI, USB, or other device passthrough removes the vulnerable code path that the newly disclosed flaw exploits, forcing each guest to use only emulated or paravirtualized devices that remain under the hypervisor's complete control. This action immediately reduces the probability of guest-to-host escape without waiting for patch deployment. Network segmentation, key placement, and memory deduplication do not address the hypervisor interface that the exploit targets, so they provide little or no protection against the initial breakout.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a hypervisor privilege-escalation (VM-escape) flaw?
Open an interactive chat with Bash
What does device passthrough mean in virtualization?
Open an interactive chat with Bash
How does disabling device passthrough protect against hypervisor flaws?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .