Soru

Zorluk: OrtaData Protection and Storage Security Architecture

An autonomous vehicle research firm stores large volumes of sensor telemetry and machine learning datasets on distributed block storage arrays. The security team needs to protect data at rest against physical drive theft from the data center while minimizing processor performance impact on host hypervisors. Which of the following storage security controls best satisfies this requirement?

  1. Implementing Self-Encrypting Drives (SEDs) with dedicated cryptographic hardware built into the disk controllersCevap
  2. B
    Deploying software-based asymmetric encryption using RSA-4096 across all hypervisors before writing blocks to storage
  3. C
    Configuring IPsec encrypted tunnels for all storage traffic between the hypervisors and storage network switches
  4. D
    Installing an inline Data Loss Prevention (DLP) network appliance to encrypt block-level SAN storage pools

Cevap

Implementing Self-Encrypting Drives (SEDs) with dedicated cryptographic hardware built into the disk controllers
Implementing Self-Encrypting Drives (SEDs) provides hardware-assisted encryption directly on the drive controller. This ensures that all data written to the drive is encrypted at rest using symmetric ciphers without introducing computational overhead on the host hypervisors.

Adım Adım Çözüm

1
Analyze the technical requirements in the scenario.
Identified two key criteria: protecting data at rest against physical drive theft, and avoiding host hypervisor CPU performance penalties.
Storage security architectures must balance security guarantees with system throughput and host overhead.
2
Evaluate hardware offload vs software encryption solutions.
Hardware-based encryption integrated into storage drive controllers (SEDs) offloads cryptographic operations completely from the host CPU.
SEDs encrypt data seamlessly at media line rate using onboard hardware keys.
3
Select the appropriate storage control.
SED deployment fulfills both data-at-rest protection and zero host CPU performance degradation requirements.
Disks automatically decrypt content upon authorized drive controller power-up, securing stolen media when powered off.

Anahtar Kavram

Data at Rest Encryption and Self-Encrypting Drives (SED)
Bu soruyu puanla