Soru

Zorluk: Çok zorData Protection and Storage Security Architecture

Match each storage security control mechanism to its corresponding enterprise architectural objective.

  • LUN Masking and Fabric ZoningRestricts storage volume visibility across a SAN fabric by binding logical unit numbers to host bus adapter identifiers and switch ports.
  • KMIP-integrated Hardware Security Module (HSM)Provides an enterprise root-of-trust and standardized key lifecycle management for heterogeneous storage arrays.
  • Exact Data Matching (EDM) DLPDetects exfiltration of structured sensitive records by inspecting outbound data against pre-computed index hashes.
  • Format-Preserving Encryption (FPE)Encrypts sensitive data strings while preserving original length and character set constraints for application schema compatibility.

Cevap

The correct pairings match LUN Masking and Fabric Zoning with SAN volume isolation, KMIP-integrated HSM with centralized key management root-of-trust, Exact Data Matching DLP with hashed database record inspection, and Format-Preserving Encryption with format-constrained ciphertext transformation.
Each storage security technology fulfills a distinct operational mandate: LUN Masking and Fabric Zoning isolate SAN storage volumes; a KMIP-integrated HSM standardizes storage encryption key lifecycles; Exact Data Matching DLP inspects outbound traffic using database record hashes; and Format-Preserving Encryption secures stored values while maintaining original database field formats.

Adım Adım Çözüm

1
Analyze SAN boundary security controls
LUN Masking and Fabric Zoning segment network traffic and restrict volume access at the storage controller and switch tier based on host HBA identity.
This isolates storage logical units from unauthorized hosts on the shared storage network.
2
Evaluate key management architecture for bulk storage encryption
A KMIP-integrated HSM centralizes key generation, storage, and distribution across disparate storage arrays.
KMIP enables standardized communication between key management servers and storage clients.
3
Identify structured data exfiltration prevention controls
Exact Data Matching (EDM) relies on database hashes to pinpoint sensitive structured records leaving the network.
EDM reduces false positives compared to standard pattern matching when monitoring data in transit.
4
Determine data-at-rest obfuscation for legacy database schemas
Format-Preserving Encryption maintains field lengths and character sets during encryption.
FPE satisfies compliance encryption requirements without breaking database constraints.

Anahtar Kavram

Enterprise Storage Security Architecture and Data Protection Controls
Bu soruyu puanla