Soru

Zorluk: OrtaData Protection and Storage Security Architecture

A security architect is updating the enterprise storage protection strategy to safeguard sensitive data at rest and during access operations. Match each storage security control on the left with its primary operational mechanism on the right.

  • Storage Area Network (SAN) LUN MaskingRestricts storage volume access to authorized host World Wide Names (WWNs) or iSCSI initiators at the controller layer.
  • Hardware Security Module (HSM)Provides tamper-resistant hardware for central generation, storage, and lifecycle management of root encryption keys.
  • Database TokenizationReplaces sensitive data elements with non-sensitive surrogate tokens, preserving database schema without using mathematical ciphers.
  • Endpoint Data Loss Prevention (DLP)Monitors local drive activity and removable media operations to prevent unauthorized extraction of confidential data.

Cevap

SAN LUN Masking maps to restricting storage volume access by host WWNs/iSCSI initiators. Hardware Security Module (HSM) maps to tamper-resistant hardware key lifecycle management. Database Tokenization maps to replacing sensitive data elements with non-sensitive surrogate tokens. Endpoint Data Loss Prevention (DLP) maps to monitoring local drive and removable media operations to prevent unauthorized data extraction.
Each storage security control fulfills a distinct architectural role: SAN LUN masking controls host-level access to SAN storage volumes, HSM safeguards root cryptographic keys in dedicated physical hardware, Tokenization obfuscates sensitive values without mathematical key ciphering, and Endpoint DLP prevents local data exfiltration.

Adım Adım Çözüm

1
Analyze storage access controls.
SAN LUN masking configures storage controllers to restrict logical unit number exposure to authorized host identifiers (WWNs/iSCSI initiators).
This enforces storage isolation in SAN environments.
2
Analyze cryptographic hardware controls.
HSM protects key management operations inside tamper-evident physical boundaries.
This prevents root key exposure or theft.
3
Analyze data protection and obfuscation controls.
Tokenization substitutes sensitive fields with non-sensitive tokens while storing mapping tables securely.
This reduces regulatory scope while preserving database formatting.
4
Analyze data loss prevention controls.
Endpoint DLP inspects local endpoints to prevent unauthorized copying of sensitive files to removable storage.
This mitigates insider threat and accidental data exfiltration.

Anahtar Kavram

Enterprise Data Protection and Storage Architecture Controls
Bu soruyu puanla