Match each virtualization or containerization security control on the left with its corresponding primary isolation capability on the right.
- Type 1 HypervisorExecutes directly on host hardware to provide virtual machine isolation.
- Control Groups (cgroups)Limits and allocates system resources such as CPU and memory usage per container.
- NamespacesRestricts container visibility into host kernel resources, isolating process IDs and network interfaces.
- MicrosegmentationEnforces granular network traffic policies to isolate individual workload instances.
Cevap
Type 1 Hypervisor pairs with bare-metal hardware execution; Control Groups (cgroups) pair with resource allocation limits; Namespaces pair with kernel view isolation; Microsegmentation pairs with granular network traffic isolation.
Each isolation control serves a specific functional role: Type 1 hypervisors execute on bare-metal hardware, control groups (cgroups) regulate host resource allocation per container, namespaces partition kernel visibility to restrict process boundaries, and microsegmentation enforces granular network traffic rules between virtual workloads.
Adım Adım Çözüm
Anahtar Kavram
Virtualization and Container Isolation Mechanisms