A single hypervisor hosts both a low-trust guest Wi-Fi captive portal VM and finance application VMs with weak isolation controls. Leadership asks what vulnerability would let an attacker break out of the portal guest. Which concept applies?
Select an answer to reveal the explanation.
Short Explanation
If malware in the guest Wi-Fi portal can climb into the hypervisor or next-door finance VMs, that is VM escape — isolation just failed. Keep low-trust and high-trust workloads apart; SMS phishing and public buckets are different headaches. Hypervisor patching and segregation matter for civic mixed tenancy.
Full Explanation
VM escape is a virtualization vulnerability where an attacker leaves a guest and impacts the host or other guests, defeating isolation. Objective 2.3 lists virtualization/VM escape risks. Smishing, typosquatting BEC, and public cloud buckets are separate vectors or misconfigurations. Municipal hypervisors should avoid co-locating low-trust portals with sensitive finance VMs without strong isolation and patching.