another call for VMs. the host is isolated from the normal network and has an isolated backup. Then when the guests are infected you first power them off forcefully. recover from backup. carry of as normal.

if the guests can get to the hosts then you are doing something wrong. the whole point of having a management network is to keep your infrastructure away from production network.

