Soru

Zorluk: OrtaData Protection and Storage Security Architecture

A storage administrator at a financial enterprise is tasked with securing sensitive transaction logs stored on a high-throughput Storage Area Network (SAN). The solution must protect data at rest against physical drive theft from the data center without introducing computational overhead on the host servers or latency into bulk disk operations. Which of the following storage security controls best satisfies these requirements?

  1. Deploying Self-Encrypting Drives (SEDs) utilizing dedicated hardware controllers and symmetric AES block encryptionCevap
  2. B
    Configuring host-based software volume encryption that utilizes asymmetric RSA key pairs for every disk block write operation
  3. C
    Implementing OS-level cryptographic hashing on all storage volumes to secure data confidentiality against physical theft
  4. D
    Installing inline network firewalls between SAN storage switches to serve as a compensating control for physical drive theft

Cevap

Deploying Self-Encrypting Drives (SEDs) utilizing dedicated hardware controllers and symmetric AES block encryption.
Self-Encrypting Drives (SEDs) incorporate dedicated cryptographic hardware directly onto the drive controller. They utilize fast symmetric algorithms (such as AES) to perform transparent encryption and decryption at media speed, ensuring zero processing burden on host CPU resources while protecting data at rest if physical drives are stolen.

Adım Adım Çözüm

1
Analyze the scenario constraints and security objectives.
The requirement calls for data-at-rest protection against physical theft, zero host CPU overhead, and minimal latency for high-throughput SAN storage.
Host-based cryptographic processing reduces available server computing resources for applications.
2
Evaluate hardware-based versus software-based storage encryption mechanisms.
Hardware-based encryption handled directly at the drive media layer (SEDs) offloads cryptographic processing from host systems while enforcing transparent bulk data protection.
SED controllers encrypt data seamlessly as it is written to media using fast symmetric block ciphers.
3
Select the correct storage control matching all enterprise criteria.
Self-Encrypting Drives (SEDs) with symmetric encryption satisfy the performance, host load, and confidentiality requirements.
Hardware SED implementation satisfies all constraint parameters efficiently.

Anahtar Kavram

Hardware-based Storage Encryption & Data at Rest Protection
Bu soruyu puanla