Soru

Zorluk: KolayData Protection and Storage Security Architecture

A system administrator needs to protect sensitive data stored on enterprise storage drives against physical theft while ensuring that the underlying cryptographic keys are securely generated and managed using a dedicated hardware appliance. Which of the following technical controls should be implemented to fulfill these requirements? (Select TWO)

  1. Self-Encrypting Drives (SEDs) to perform automatic hardware-level data-at-rest encryptionCevap
  2. Hardware Security Module (HSM) for centralized, secure cryptographic key generation and storageCevap
  3. C
    Asymmetric RSA encryption for high-speed bulk storage disk encryption
  4. D
    Cryptographic hash functions applied to stored files to ensure non-repudiation of data creation
  5. E
    Inline network firewalls to mitigate physical hard drive theft from storage arrays

Cevap

The correct technical controls are implementing Self-Encrypting Drives (SEDs) for hardware-level data-at-rest encryption and deploying a Hardware Security Module (HSM) for secure key management.
Implementing Self-Encrypting Drives (SEDs) ensures that data on physical disk drives is encrypted automatically at rest, safeguarding data against physical drive theft. Pairing SEDs with a Hardware Security Module (HSM) provides a hardened, dedicated physical appliance to securely generate, store, and manage the cryptographic keys required for storage protection.

Adım Adım Çözüm

1
Identify the control required for hardware-level data-at-rest protection against physical theft
Self-Encrypting Drives (SEDs) encrypt disk sectors automatically via onboard hardware, preventing unauthorized data access if the drive is physically removed.
SEDs provide disk encryption at rest directly on the storage hardware.
2
Identify the dedicated hardware control for cryptographic key management
A Hardware Security Module (HSM) provides a tamper-resistant environment specialized for key generation, storage, and protection.
HSMs meet the requirement for centralized and secure key lifecycle operations.

Anahtar Kavram

Data Protection at Rest and Cryptographic Storage Architecture
Tahmini Süre:1m 0s
Bu soruyu puanla