Match each storage security technology on the left with its primary enterprise implementation role on the right.
- Self-Encrypting Drive (SED)Performs transparent, hardware-based disk encryption directly at the drive controller level without host CPU overhead.
- Hardware Security Module (HSM)Provides tamper-resistant, dedicated hardware storage for securing high-assurance root cryptographic key lifecycles.
- Storage Area Network (SAN) LUN MaskingRestricts host access to specific logical storage volumes on a shared disk array based on host bus adapter (HBA) identifiers.
- Endpoint Data Loss Prevention (DLP)Inspects data write operations in real time to prevent unencrypted sensitive information from leaving managed hosts to unapproved USB media.
Answer
Self-Encrypting Drive pairs with transparent hardware-based disk encryption at the drive controller level. Hardware Security Module pairs with tamper-resistant hardware storage for securing key lifecycles. SAN LUN Masking pairs with restricting host access to specific logical volumes based on HBA identifiers. Endpoint DLP pairs with inspecting data write operations to prevent unencrypted sensitive data transfers to removable media.
Each technology fulfills a distinct role within enterprise storage architecture: SEDs provide transparent drive controller-level hardware encryption; HSMs secure key storage in hardened modules; SAN LUN masking restricts volume access by host identifier; and endpoint DLP enforces data content protection policies on endpoint write actions.
Step-by-Step Solution
Key Concept
Data Protection and Storage Security Architecture