ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a design review, you learn that the company's private cloud uses a Type-2 hypervisor installed on top of a general-purpose host operating system. Management wants to reduce the hypervisor's exposed attack surface and lower the likelihood of hyperjacking while continuing to run the same guest virtual machines. Which architectural change would provide the greatest security improvement?
Replace the hosted platform with a bare-metal (Type-1) hypervisor that uses hardware-assisted virtualization and secure boot.
Deploy host-based intrusion detection systems inside every guest virtual machine.
Increase the host operating system's logging level and forward hypervisor logs to the SIEM.
Configure VLAN tagging on the virtual switch to isolate traffic between guest networks.
Because a Type-2 (hosted) hypervisor relies on a full host operating system and its services, it presents a larger attack surface that attackers can target for hyperjacking. Migrating to a bare-metal (Type-1) hypervisor removes the dependency on a separate host OS, substantially reducing code complexity and potential vulnerabilities. While host-based IDS, VLAN segmentation, and enhanced logging are useful defense-in-depth measures, none address the fundamental exposure created by the hosted architecture itself, so they provide less risk reduction than adopting a Type-1 hypervisor with hardware-assisted virtualization and secure boot support.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between a Type-1 and Type-2 hypervisor?
Open an interactive chat with Bash
What is hyperjacking, and how does it affect virtualized environments?
Open an interactive chat with Bash
What is hardware-assisted virtualization and why is it important for security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .