nerdexam
Hitachi

HAT-420 · Question #94

What are two ways to restrict access to storage through a Fabric? (Choose two.)

Zoning (B) and port security on the switch(es) (D) are the two correct methods for restricting access to storage through a Fabric. Zoning is the primary SAN Fabric security mechanism - it logically partitions the fabric so that only devices within the same zone can communicate…

Basic Configuration and Initialization

Question

What are two ways to restrict access to storage through a Fabric? (Choose two.)

Options

  • AUse SNMP
  • BUse zoning
  • CUse Host Group security
  • DUseport security on the switch(es)

Explanation

Zoning (B) and port security on the switch(es) (D) are the two correct methods for restricting access to storage through a Fabric.

Zoning is the primary SAN Fabric security mechanism - it logically partitions the fabric so that only devices within the same zone can communicate, preventing unauthorized hosts from seeing storage targets. Port security (also called port binding) locks a specific WWN to a specific switch port, so an unauthorized device physically plugging into that port cannot join the fabric.

SNMP (A) is a network monitoring and management protocol - it collects device statistics and sends alerts, but does not enforce access restrictions. Host Group security (C) is a storage-array-level concept (grouping hosts for LUN masking), not a Fabric-level control - it operates on the array, not within the switch infrastructure.

Memory tip: Think "Fabric = Switch infrastructure." Both correct answers operate on the switches themselves - zoning is logical partitioning, port security is physical-port binding. If the control lives on the array or in a management protocol, it's not a Fabric-level restriction.

Topics

#SAN access control#fabric zoning#port security#storage security

Community Discussion

No community discussion yet for this question.

Full HAT-420 Practice