A enterprise cloud services provider is decommissioning a high-density, multi-tenant Storage Area Network (SAN) array containing sensitive tenant data. The SAN storage tier utilizes Self-Encrypting Drives (SEDs) configured to manage media encryption keys via a centralized Key Management Interoperability Protocol (KMIP) cluster. Due to lease agreements, the physical NVMe solid-state drives must remain intact and intact hardware must be returned to the lessor within a strict two-hour window. Which of the following technical procedures provides the most effective and cryptographically sound method to ensure all tenant data is permanently unrecoverable before the drives are removed?
- Instruct the centralized KMIP server to purge the Media Encryption Keys (MEKs) or Key Encryption Keys (KEKs) associated with the SED array to execute cryptographic erasure.Cevap
- BExecute a full multi-pass zeroization and block-overwrite utility across all physical NVMe drive sectors directly from the storage controller console.
- CReconfigure Fibre Channel switch zoning and LUN masking rules to clear all Host Bus Adapter (HBA) World Wide Names (WWNs) associated with the storage array.
- DRe-encrypt the raw block volumes at the host level using an asymmetric RSA-4096 public key pair before unmounting the storage pools.
Cevap
Destroying or purging the Key Encryption Keys (KEKs) or Media Encryption Keys (MEKs) on the centralized KMIP server to perform cryptographic erasure (crypto-shredding) is the most effective approach.
Cryptographic erasure (crypto-shredding) relies on deleting the encryption key (MEK/KEK) that protects encrypted data at rest. Because the storage array utilizes Self-Encrypting Drives integrated with a KMIP key manager, purging the keys on the KMIP cluster renders all underlying block data instantaneously unrecoverable while leaving physical drive hardware completely undamaged.
Adım Adım Çözüm
Anahtar Kavram
Cryptographic Erasure (Crypto-shredding) & Centralized Key Management (KMIP)