nerdexam
Dell-EMC

E10-001 · Question #142

Which SAN security mechanism will prevent a switch port from being enabled even after a switch reboot?

The correct answer is A. Persistent Port Disable. Securing FC Switch Ports Apart from zoning and LUN masking, additional security mechanisms, such as port binding, port lockdown, port lockout, and persistent port disable, can be implemented on switch ports. Port binding: Limits the devices that can attach to a particular…

Securing Storage Infrastructure

Question

Which SAN security mechanism will prevent a switch port from being enabled even after a switch reboot?

Options

  • APersistent Port Disable
  • BPort Binding
  • CPort Lockdown
  • DPersistent Switch Disable

How the community answered

(37 responses)
  • A
    73% (27)
  • B
    8% (3)
  • C
    16% (6)
  • D
    3% (1)

Explanation

Securing FC Switch Ports Apart from zoning and LUN masking, additional security mechanisms, such as port binding, port lockdown, port lockout, and persistent port disable, can be implemented on switch ports. Port binding: Limits the devices that can attach to a particular switch port and allows only the corresponding switch port to connect to a node for fabric access. Port binding mitigates but does not eliminate WWPN spoofing. Port lockdown and port lockout: Restrict a switch port's type of initialization. Typical variants of port lockout ensure that the switch port cannot function as an E-Port and cannot be used to create an ISL, such as a rogue switch. Some variants ensure that the port role is restricted to only F-Port, E-Port, or a combination of these. Persistent port disable: Prevents a switch port from being enabled even after a switch reboot.

Topics

#SAN security#persistent port disable#switch port security#fabric hardening

Community Discussion

No community discussion yet for this question.

Full E10-001 Practice