A pharmaceutical research organization is updating its storage architecture to host confidential genomic sequencing datasets. The security architect must satisfy two primary requirements: guarantee bulk data encryption at rest on storage area network (SAN) arrays without degrading host processing performance, and prevent research data from being copied to unauthorized physical media or unapproved endpoints. Which of the following technical security solutions should the architect select to meet these requirements? (Select TWO)
- Deploy Self-Encrypting Drives (SEDs) utilizing hardware-based cryptographic controllers on the SAN storage arraysCevap
- BImplement software-based asymmetric RSA encryption across all bulk storage volumes
- Deploy an enterprise Data Loss Prevention (DLP) solution configured with endpoint and storage monitoring policiesCevap
- DConfigure RAID 5 array striping across storage pools to establish data non-repudiation
- EInstall perimeter network firewalls to block physical data transfers to external USB media
Cevap
The architect should deploy Self-Encrypting Drives (SEDs) on the SAN storage arrays and implement an enterprise Data Loss Prevention (DLP) solution with endpoint monitoring policies.
Deploying Self-Encrypting Drives (SEDs) satisfies the requirement for transparent, hardware-accelerated bulk data encryption without imposing software encryption overhead on host CPUs. Implementing Data Loss Prevention (DLP) directly controls data movements on endpoints, enforcing rules to inspect content and block unauthorized file transfers to removable media.
Adım Adım Çözüm
Anahtar Kavram
Data Protection and Storage Security Architecture