Soru

Zorluk: OrtaData Protection and Storage Security Architecture

An enterprise organization is deploying a centralized storage architecture hosting high-value transactional databases. Compliance regulations require that all storage volumes maintain encryption at rest, and master cryptographic keys must be generated, safeguarded, and offloaded to dedicated hardware isolated from host OS administrators to prevent unauthorized key extraction. Which of the following solutions should the security architect integrate into the storage architecture to fulfill this key management requirement?

  1. Hardware Security Module (HSM)Cevap
  2. B
    Bulk asymmetric encryption using RSA-4096 keys across all storage blocks
  3. C
    SHA-256 cryptographic hashing to guarantee non-repudiation of stored data
  4. D
    Inline perimeter firewalls with deep packet inspection on storage networks

Cevap

Hardware Security Module (HSM)
A Hardware Security Module (HSM) is a hardened, physical computing device that safeguards and manages digital keys, performs encryption and decryption functions, and generates strong random cryptographic keys. By storing master keys inside an HSM, key extraction by host operating system administrators or malware is prevented.

Adım Adım Çözüm

1
Analyze the enterprise security requirement
Identified the core requirement: isolating cryptographic key generation and management into dedicated hardware separate from the host OS.
Host operating systems and hypervisors can be compromised by privilege escalation or unauthorized administrative key extraction.
2
Evaluate potential storage protection and key management solutions
Determined that a Hardware Security Module (HSM) provides physical isolation, tamper resistance, and secure key lifecycle management.
HSMs meet regulatory standards (such as FIPS 140-2/140-3) for key isolation and offloaded cryptographic processing.

Anahtar Kavram

Hardware-Based Key Protection and Storage Security Architecture
Bu soruyu puanla