Soru

Zorluk: ZorData Protection and Storage Security Architecture

A healthcare enterprise is architecting a storage and data security solution for its electronic health record (EHR) database environment. The design must ensure bulk data at rest remains cryptographically secured without causing significant performance overhead on database queries, while also preventing unauthorized exfiltration of sensitive patient records across endpoint storage interfaces and removable media. Which of the following security controls should the architect integrate to satisfy these requirements? (Select TWO.)

  1. Deploy symmetric envelope encryption or hardware-accelerated volume encryption (such as AES-256) for the underlying storage subsystem.Cevap
  2. B
    Utilize asymmetric RSA-4096 key pairs for bulk block-level encryption of the enterprise database volumes.
  3. Implement endpoint Data Loss Prevention (DLP) software agents to inspect, classify, and enforce contextual blocking on local storage transfers.Cevap
  4. D
    Configure perimeter firewalls to generate SHA-256 cryptographic hashes for all outbound data transfers to enforce non-repudiation.
  5. E
    Deploy network-level intrusion detection systems (IDS) as the primary control to prevent bulk data copy operations to external USB drives.

Cevap

The correct architecture controls are deploying symmetric encryption (such as AES-256) for bulk storage volume protection and implementing endpoint Data Loss Prevention (DLP) agents for endpoint storage exfiltration control.
Protecting bulk data at rest efficiently requires high-speed symmetric ciphers (such as AES-256) at the storage volume level, which ensures strong confidentiality without computational performance degradation. Preventing data exfiltration to endpoint storage devices requires endpoint Data Loss Prevention (DLP) agents that monitor and enforce policy rules on data in use and local storage interfaces.

Adım Adım Çözüm

1
Analyze storage encryption at rest requirements for high-performance database workloads.
Bulk encryption requires fast, hardware-accelerated symmetric ciphers like AES-256 to avoid severe query latency.
Symmetric ciphers use a single secret key and process bulk data efficiently compared to asymmetric ciphers.
2
Evaluate data exfiltration protection across endpoint storage and removable media.
Host/endpoint DLP agents inspect content and context on the local machine to block unauthorized transfers to removable storage.
Network-based controls cannot see or restrict local device bus transfers like USB writes.

Anahtar Kavram

Data Protection and Storage Security Architecture
Bu soruyu puanla