Soru

Zorluk: OrtaData Protection and Storage Security Architecture

A financial services organization is designing a high-throughput database storage system that requires transparent, hardware-level data encryption at rest without burdening the host database server CPUs. Additionally, organizational compliance mandates that encryption keys must be generated and lifecycle-managed by a centralized external key appliance. Which of the following storage security solutions best fulfills these requirements?

  1. Self-Encrypting Drives (SEDs) integrated with a centralized key manager using Key Management Interoperability Protocol (KMIP)Cevap
  2. B
    Application-level asymmetric RSA encryption applied to bulk database tables before writing data to storage
  3. C
    Inline network firewalls enforcing deep-packet inspection and TLS decryption across storage area network switches
  4. D
    SIEM event correlation rules configured to trigger real-time dynamic data masking during database queries

Cevap

Deploying Self-Encrypting Drives (SEDs) integrated with a Key Management Interoperability Protocol (KMIP) server
Self-Encrypting Drives (SEDs) perform full disk bulk encryption at the drive controller hardware layer using fast symmetric ciphers (such as AES), which prevents host CPU overhead. Leveraging the Key Management Interoperability Protocol (KMIP) allows the drive hardware to offload key generation, rotation, and escrow to a centralized enterprise key management appliance.

Adım Adım Çözüm

1
Evaluate host performance requirements for data-at-rest encryption
Selected hardware-based encryption on the storage drive controller rather than host-based software encryption to avoid host CPU degradation
Self-Encrypting Drives (SEDs) handle AES bulk encryption transparently on dedicated hardware on the drive itself.
2
Evaluate key management governance requirements
Identified KMIP integration for centralized key management
KMIP enables enterprise storage hardware to retrieve and manage encryption keys securely from a centralized Hardware Security Module (HSM) or key management server.

Anahtar Kavram

Hardware-based Storage Encryption & Centralized Key Management
Bu soruyu puanla