Soru

Zorluk: ZorData Protection and Storage Security Architecture

A enterprise storage architect is designing a secure storage architecture for an off-site media storage facility and cloud synchronization gateway that processes large volumes of sensitive customer transactional data. The solution must ensure bulk encryption of data at rest with minimal CPU overhead, enforce hardware-isolated key protection to prevent key extraction, and prevent unauthorized exfiltration of unencrypted sensitive data across network egress interfaces. Which of the following technological controls should the architect incorporate into the architecture design to meet these requirements? (Select TWO.)

  1. Self-Encrypting Drives (SEDs) leveraging hardware-based AES-256 transparent encryptionCevap
  2. Hardware Security Module (HSM) deployed to manage and safeguard root keys and Key Encryption Keys (KEKs)Cevap
  3. C
    Asymmetric RSA-4096 cryptosystems applied directly to bulk database file blocks at rest
  4. D
    Network-level Data Loss Prevention (DLP) solution inspecting outbound traffic at the network egress perimeter
  5. E
    SHA-512 cryptographic hashing applied to all stored media to guarantee non-repudiation of transactions

Cevap

The enterprise storage architecture should implement Self-Encrypting Drives (SEDs) utilizing AES-256 hardware encryption alongside a dedicated Hardware Security Module (HSM) for root key protection.
Implementing Self-Encrypting Drives provides high-speed, hardware-based symmetric encryption at rest (AES-256) without host CPU penalties. Pairing SEDs with a Hardware Security Module ensures key generation and protection occur inside a hardware-isolated, tamper-evident boundary.

Adım Adım Çözüm

1
Evaluate bulk data encryption requirements for storage at rest.
Self-Encrypting Drives (SEDs) handle hardware-level symmetric bulk encryption directly on the drive controller, ensuring high performance without burdening system CPUs.
Bulk storage requires fast symmetric algorithms (like AES) offloaded to specialized hardware controllers.
2
Identify key management controls for hardware isolation.
A Hardware Security Module (HSM) provides physical and logical tamper-resistant boundaries to generate, store, and manage master keys and KEKs.
HSMs ensure cryptographic keys cannot be extracted in plaintext by unauthorized users or compromised OS layers.

Anahtar Kavram

Data Protection at Rest and Storage Hardware Security Architecture
Bu soruyu puanla