ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team must integrate an untrusted data analytics plugin into a Linux-based microservices platform. The plugin needs near-native performance but must be confined so it cannot access files beyond its working directory or affect other services. Which isolation technique offers the most appropriate balance of strong operating-system-level separation and minimal performance overhead?
Execute the plugin within the same process under a language runtime sandbox (e.g., Java SecurityManager).
Place the plugin in a traditional chroot jail on the host operating system.
Run the plugin inside a container that leverages Linux namespaces and cgroups for isolation.
Run the plugin in a full hardware-assisted virtual machine with its own guest operating system.
Containers implement operating-system-level virtualization using namespaces and cgroups to restrict a process's view of the filesystem, process table, network stack, and resource consumption. Because containers share the host kernel, they avoid the heavy memory and CPU overhead of running a full guest operating system, delivering performance close to bare metal while still providing substantially stronger isolation than simple chroot jails or language runtimes. Full virtual machines give robust isolation but add significant resource and management overhead, while chroot and language-based sandboxes rely on discretionary mechanisms that are easier to bypass. Therefore, running the plugin inside a container is the best choice for secure, efficient isolation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Linux namespaces and cgroups?
Open an interactive chat with Bash
How do containers differ from virtual machines?
Open an interactive chat with Bash
Why is chroot considered less secure than containers?
Open an interactive chat with Bash
What are Linux namespaces and how do they contribute to container isolation?
Open an interactive chat with Bash
What are cgroups in Linux, and how do they manage resource allocation in containers?
Open an interactive chat with Bash
Why are containers more efficient than full virtual machines for plugin isolation?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .