nerdexam
Dell-EMC

E20-393 · Question #34

Where do the D@RE encryption/decryption functions occur In the Unity storage system?

The correct answer is C. SAS I/O Module. Upon installation and activation of the feature, the following keys are generated by RSA BSAFE and persisted to the Lockbox: KEK Wrapping Key (KWK) Data Encryption Keys (DEKs) for all bound drives A new KEK is generated each time the array boots. The KEK is wrapped with the KWK…

Understand Dell EMC Unity Architecture and Features

Question

Where do the D@RE encryption/decryption functions occur In the Unity storage system?

Options

  • AHost I/O Modules
  • BStorage Processor Cache
  • CSAS I/O Module
  • DSelf-encrypting drives

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    75% (18)
  • D
    8% (2)

Explanation

Upon installation and activation of the feature, the following keys are generated by RSA BSAFE and persisted to the Lockbox: KEK Wrapping Key (KWK) Data Encryption Keys (DEKs) for all bound drives A new KEK is generated each time the array boots. The KEK is wrapped with the KWK and passed to the SAS controller during the system boot process. Using the persisted KWK, the SAS controller can decrypt the KEK. Incorrect Answers: D: Self-Encrypting Drive (SED) technology is another variation of D@RE which is widely used and offers similar functionality as CBE. However, with SEDs, you have to pay a premium on every drive and only certain drivesare offered in SED form.

Topics

#D@RE#encryption#SAS I/O Module#Storage Processor

Community Discussion

No community discussion yet for this question.

Full E20-393 Practice