Soru

Zorluk: OrtaData Protection and Storage Security Architecture

A security engineer is designing a secure storage architecture for an enterprise financial organization migrating sensitive customer records to a public cloud object storage environment. To meet compliance standards and protect data at rest against unauthorized cloud administrator access and physical disk theft, which of the following controls should the engineer implement? (Select TWO).

  1. Client-side bulk data encryption using symmetric AES-256 with key management integrated into a dedicated Hardware Security Module (HSM)Cevap
  2. Storage-integrated Data Loss Prevention (DLP) policies paired with automated data classification tagsCevap
  3. C
    Asymmetric RSA-4096 block-level encryption for high-throughput bulk database volume storage
  4. D
    Standalone SHA-256 cryptographic file hashing to establish non-repudiation against internal data deletion
  5. E
    Inline Web Application Firewall (WAF) filtering configured as a corrective security control to repair corrupted storage sectors

Cevap

The correct controls to implement are client-side bulk data encryption using symmetric AES-256 with HSM key management, and storage-integrated Data Loss Prevention (DLP) policies paired with automated data classification tags.
Client-side symmetric encryption (AES-256) backed by an HSM ensures high-speed bulk data protection and complete customer key ownership before data reaches public cloud storage. Storage-integrated DLP with automated classification enforces content-aware authorization and exfiltration monitoring across the storage repository.

Adım Adım Çözüm

1
Analyze storage encryption requirements for bulk data at rest.
Identify that client-side bulk storage protection requires fast symmetric encryption (AES-256) managed via dedicated key management hardware (HSM) to protect data before it reaches third-party infrastructure.
Symmetric ciphers provide efficient bulk encryption, while client-side HSM key management prevents unauthorized access by cloud administrators or compromised physical storage media.
2
Analyze data discovery and access monitoring controls.
Identify that Data Loss Prevention (DLP) coupled with data classification tags prevents unauthorized exfiltration and enforces policy compliance on sensitive customer records.
DLP mechanisms contextualize data based on sensitivity labels and monitor access patterns within the storage architecture.
3
Evaluate remaining choices against cryptographic and security control principles.
Reject asymmetric RSA for bulk storage due to performance constraints, reject hashing for non-repudiation because hashes lack origin proof/digital signatures, and reject WAF as a storage sector repair tool because WAFs are application-layer preventive filters.
Aligns with core principles regarding cipher selection, AAA/integrity mechanisms, and security control functional classification.

Anahtar Kavram

Data Protection and Storage Security Architecture
Bu soruyu puanla