nerdexam
CompTIA

SG0-001 · Question #265

University IT provides shared Fibre Channel storage services. All storage subsystems and fibre channel switches are located in the secure campus datacenter. Each college and department provides their

The correct answer is D. port authentication. In a shared Fibre Channel environment where central IT provides fabric, storage, and backup, but individual departments manage their own systems, controlling access to specific storage resources is paramount.

Storage Connectivity

Question

University IT provides shared Fibre Channel storage services. All storage subsystems and fibre channel switches are located in the secure campus datacenter. Each college and department provides their own systems and staff. Central IT provides fabric, storage and backup administration. Which security mechanism is most important in this Fibre Channel infrastructure?

Options

  • AFCPAP
  • Blink encryption
  • Cswitch authentication
  • Dport authentication

How the community answered

(20 responses)
  • A
    5% (1)
  • C
    10% (2)
  • D
    85% (17)

Why each option

In a shared Fibre Channel environment where central IT provides fabric, storage, and backup, but individual departments manage their own systems, controlling access to specific storage resources is paramount.

AFCPAP

FCPAP is a security protocol for authenticating entities connecting to the fabric, but it does not directly control granular host-to-storage access or resource segregation within the fabric.

Blink encryption

Link encryption protects data confidentiality in transit over the Fibre Channel link but does not provide access control or restrict which hosts can access specific storage resources.

Cswitch authentication

Switch authentication verifies the identity of Fibre Channel switches for fabric integrity and trust, but it does not manage host-level access to storage resources within the fabric.

Dport authenticationCorrect

Port authentication, often implemented through Fibre Channel zoning (e.g., WWN zoning) and LUN masking, is critical in a shared SAN. It ensures that only authorized host ports can access designated storage ports and their associated LUNs, thereby preventing unauthorized access and maintaining data segregation across different departments connected to the same fabric.

Concept tested: Fibre Channel port access control

Source: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/mds9000/sw/4_1/configuration/guides/zoning/zoning.html

Topics

#Fibre Channel security#SAN security#port authentication#shared storage

Community Discussion

No community discussion yet for this question.

Full SG0-001 Practice