Question

Difficulty: EasyData Protection and Storage Security Architecture

An IT administrator needs to ensure that all data written to enterprise storage drives is automatically encrypted at the hardware level without placing an operational processing burden on the host operating system. Which of the following storage security solutions best fulfills this requirement?

  1. Self-Encrypting Drives (SED)Answer
  2. B
    Asymmetric RSA key pairs applied to bulk file storage
  3. C
    Endpoint Data Loss Prevention (DLP) policy enforcement
  4. D
    Host-based network firewalls configured with strict ingress rules

Answer

Self-Encrypting Drives (SED)
Self-Encrypting Drives (SEDs) incorporate dedicated cryptographic hardware directly into the drive controller. This enables transparent, full-disk symmetric encryption at rest without consuming host CPU cycles or requiring operating system software configuration.

Step-by-Step Solution

1
Identify the primary system requirement in the scenario.
The requirement calls for hardware-level encryption of bulk data at rest without consuming host OS processing resources.
Software bulk encryption relies on host CPU cycles, whereas hardware encryption offloads cryptographic tasks.
2
Evaluate storage protection mechanisms against the requirement.
Self-Encrypting Drives (SEDs) contain built-in cryptoprocessors that transparently handle symmetric encryption directly on the drive controller.
This guarantees hardware-level protection without host system latency.

Key Concept

Hardware-Based Storage Encryption and Data-at-Rest Architecture
Rate this question