Soru

Zorluk: OrtaData Protection and Storage Security Architecture

An enterprise organization is updating its hybrid storage security architecture to enhance protection for sensitive databases stored on storage area networks (SAN) and prevent unauthorized exfiltration of proprietary data. The security team requires a solution that provides dedicated hardware-backed key protection for disk volume encryption keys, as well as real-time content inspection of egress traffic to block unauthorized data transfers. Which of the following technical controls should the security architect select to meet these requirements? (Select TWO.)

  1. Deployment of a Hardware Security Module (HSM) to generate, store, and manage key encryption keys (KEKs) for disk volume protection.Cevap
  2. Implementation of a Network-based Data Loss Prevention (DLP) solution at network perimeter egress points to inspect outbound traffic.Cevap
  3. C
    Configuration of RAID 5 disk array parity across storage nodes to prevent bulk data theft if a drive is physically stolen.
  4. D
    Application of software-based asymmetric RSA algorithms for bulk SAN volume block-level encryption.
  5. E
    Reassignment of data classification authority from business data owners to storage custodians to streamline storage access policies.

Cevap

The security architect should implement a Hardware Security Module (HSM) for dedicated cryptographic key management and a Network Data Loss Prevention (DLP) system for real-time monitoring and blocking of unauthorized data egress.
Implementing a Hardware Security Module (HSM) ensures secure, hardware-rooted management and protection of key encryption keys (KEKs) used to lock storage volume keys. Complementing this with a Network-based Data Loss Prevention (DLP) engine enables real-time deep packet inspection of egress traffic to enforce compliance policies and block sensitive data exfiltration.

Adım Adım Çözüm

1
Identify the requirement for hardware-backed encryption key protection.
Selected Hardware Security Module (HSM) deployment for cryptographic key lifecycle management.
HSMs offer tamper-resistant hardware environments for managing Key Encryption Keys (KEKs) that secure storage volume encryption keys.
2
Identify the requirement for real-time egress content inspection.
Selected Network Data Loss Prevention (DLP) solution.
Network DLP inspects protocol traffic at network boundaries to prevent sensitive files and data patterns from unauthorized exfiltration.

Anahtar Kavram

Data Protection and Storage Security Architecture
Bu soruyu puanla