HAT-420 · Question #94
What are two ways to restrict access to storage through a Fabric? (Choose two.)
Zoning (B) and port security on the switch(es) (D) are the two correct methods for restricting access to storage through a Fabric. Zoning is the primary SAN Fabric security mechanism - it logically partitions the fabric so that only devices within the same zone can communicate…
Question
What are two ways to restrict access to storage through a Fabric? (Choose two.)
Options
- AUse SNMP
- BUse zoning
- CUse Host Group security
- DUseport security on the switch(es)
Explanation
Zoning (B) and port security on the switch(es) (D) are the two correct methods for restricting access to storage through a Fabric.
Zoning is the primary SAN Fabric security mechanism - it logically partitions the fabric so that only devices within the same zone can communicate, preventing unauthorized hosts from seeing storage targets. Port security (also called port binding) locks a specific WWN to a specific switch port, so an unauthorized device physically plugging into that port cannot join the fabric.
SNMP (A) is a network monitoring and management protocol - it collects device statistics and sends alerts, but does not enforce access restrictions. Host Group security (C) is a storage-array-level concept (grouping hosts for LUN masking), not a Fabric-level control - it operates on the array, not within the switch infrastructure.
Memory tip: Think "Fabric = Switch infrastructure." Both correct answers operate on the switches themselves - zoning is logical partitioning, port security is physical-port binding. If the control lives on the array or in a management protocol, it's not a Fabric-level restriction.
Topics
Community Discussion
No community discussion yet for this question.