nerdexam
Dell-EMC

E10-001 · Question #19

As your organization's SAN environment grows, you realize there is a greater need to manage SAN security. Which mechanism is required to prevent unauthorized activity on the FC fabric for management…

The correct answer is A. Role-based access control. Securing the Management Access Domain Management access, whether monitoring, provisioning, or managing storage resources, is associated with every device within the storage network. Implementing appropriate controls for securing storage management applications is important…

Pre-Checks and Planning

Question

As your organization's SAN environment grows, you realize there is a greater need to manage SAN security. Which mechanism is required to prevent unauthorized activity on the FC fabric for management operations?

Options

  • ARole-based access control
  • BAccess control lists
  • CVSAN
  • DZoning

How the community answered

(29 responses)
  • A
    72% (21)
  • B
    3% (1)
  • C
    17% (5)
  • D
    7% (2)

Explanation

Securing the Management Access Domain Management access, whether monitoring, provisioning, or managing storage resources, is associated with every device within the storage network. Implementing appropriate controls for securing storage management applications is important because the damage that can be caused by using these applications can be far more extensive. Controlling administrative access to storage aims to safeguard against the threats of an attacker spoofing an administrator's identity or elevating privileges to gain administrative access. To protect against these threats, administrative access regulation and various auditing techniques are used to enforce accountability of users and processes. Access control should be enforced for each storage component. In some storage environments, it may be necessary to integrate storage devices with third-party authentication directories, such as Lightweight Directory Access Protocol (LDAP) or Active Directory. Security best practices stipulate that no single user should have ultimate control over all aspects of the system. It is better to assign various administrative functions by using RBAC. Auditing logged events is a critical control measure to track the activities of an administrator. However, access to administrative log files and their content must be protected. In addition, having a Security Information Management (SIM) solution supports effective analysis of the event

Topics

#FC SAN security#role-based access control#management access#fabric authorization

Community Discussion

No community discussion yet for this question.

Full E10-001 Practice