This question is derived from my previous question on Isolating Web application where two approaches were recommended.
- Apache Chroot Jail
- Isolation through Virtualization
My question is if one of the VM on which application is hosted is compromised will the virtualization layer be enough contain the vulnerable web application? Are there any other security measures need to be taken to protect other VMs?