C1000-038 · Question #31
An account you cover has received media attention. A disgruntled administrator had root access to a Linux x86 financial server, altered the boot process, and deactivated all of the security…
The correct answer is B. Enable Pervasive Encryption to protect system data sets. Pervasive Encryption is correct because it protects the data itself - encrypting data sets, logs, and communications at the hardware level using IBM Z's built-in cryptographic engines (CPACF). Even if a rogue admin disables OS-level security controls or alters the boot process…
Question
An account you cover has received media attention. A disgruntled administrator had root access to a Linux x86 financial server, altered the boot process, and deactivated all of the security measures. The result was that highly sensitive data was stolen. The account security directory would like to meet with you to determine if IBM Z has a solution that would prevent this from happening again. Which IBM Z solution will prevent this type of breach?
Options
- AActivate Integrated Cryptographic Service Facility (ICSF) along with the secure crypto
- BEnable Pervasive Encryption to protect system data sets.
- CImplement the combination of RACF, z/VM, and zSecure products.
- DUse Secure Service Container to build, deploy, and manage a systems appliance.
How the community answered
(21 responses)- A10% (2)
- B81% (17)
- C5% (1)
- D5% (1)
Explanation
Pervasive Encryption is correct because it protects the data itself - encrypting data sets, logs, and communications at the hardware level using IBM Z's built-in cryptographic engines (CPACF). Even if a rogue admin disables OS-level security controls or alters the boot process, the stolen data remains ciphertext and is therefore unreadable without the keys. This is the critical distinction: security controls protect access, but encryption protects the data regardless of whether those controls are active.
Option A is wrong because ICSF manages cryptographic services and hardware but is not by itself a data-at-rest encryption solution for the described scenario. Option C is wrong because RACF, z/VM, and zSecure all depend on security controls being active - a privileged admin who can deactivate them can circumvent this layer entirely. Option D is wrong because Secure Service Container protects containerized appliance workloads from privileged hypervisor admins, which is a narrower use case than broadly protecting sensitive data sets across the system.
Memory tip: Think of it as "encrypt the vault, not just the door." Access controls (RACF, zSecure) are the door; Pervasive Encryption is the vault - and it still protects the data even when the door is forced open.
Topics
Community Discussion
No community discussion yet for this question.