Question

Difficulty: EasyData Protection and Storage Security Architecture

A security administrator needs to protect sensitive data stored on company laptops by ensuring that storage drives automatically encrypt all data at rest at the hardware layer without relying on the host operating system. Which of the following technologies best fulfills this requirement?

  1. Self-Encrypting Drive (SED)Answer
  2. B
    Hardware Security Module (HSM)
  3. C
    Tokenization
  4. D
    Asymmetric public key encryption

Answer

Self-Encrypting Drive (SED)
Self-Encrypting Drives (SEDs) contain an integrated cryptographic processor directly on the storage controller that handles encryption and decryption automatically. Because the crypto operations occur on the drive hardware itself, encryption functions transparently and independently of the host operating system.

Step-by-Step Solution

1
Identify the primary storage security requirements from the scenario.
The requirement calls for automatic hardware-level bulk encryption of storage media independently of the host operating system.
The scenario highlights protecting data at rest on laptop drives without relying on software or operating system features.
2
Evaluate the capabilities of storage encryption options.
A Self-Encrypting Drive (SED) includes onboard cryptographic hardware built into the disk controller that transparently encrypts data written to the drive.
SEDs perform media encryption directly within the drive controller microchip.

Key Concept

Hardware-Based Storage Encryption (SED)
Estimated Time:1m 0s
Rate this question