nerdexam
CompTIA

SG0-001 · Question #319

University IT has its storage subsystems and fabric switches distributed throughout the campus. Each college and department provides their own systems and staff. Central IT provides fabric, storage an

The correct answer is B. switch authentication. In a distributed university SAN environment with multiple administrative domains, authenticating fabric switches is the most crucial security mechanism to protect core fabric services.

Storage Management

Question

University IT has its storage subsystems and fabric switches distributed throughout the campus. Each college and department provides their own systems and staff. Central IT provides fabric, storage and backup administration. Which security mechanism is most important to protect fabric services?

Options

  • Anode authentication
  • Bswitch authentication
  • Cport authentication
  • Dlink encryption

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    71% (20)
  • C
    7% (2)
  • D
    18% (5)

Why each option

In a distributed university SAN environment with multiple administrative domains, authenticating fabric switches is the most crucial security mechanism to protect core fabric services.

Anode authentication

Node authentication verifies the identity of host HBAs, but it does not protect the fabric itself from unauthorized switches joining the network.

Bswitch authenticationCorrect

Switch authentication, often implemented using protocols like DH-CHAP, is critical in shared or distributed Fibre Channel fabrics. It ensures that only authorized and trusted switches are allowed to join the fabric, preventing rogue switches from being introduced that could disrupt or compromise fabric services and data integrity.

Cport authentication

Port authentication validates the device connected to a specific switch port but does not prevent an entire unauthorized switch from integrating into the SAN fabric.

Dlink encryption

Link encryption protects data confidentiality and integrity over physical links but does not authenticate the fabric switches or control which switches can participate in the fabric.

Concept tested: Fibre Channel SAN fabric security - switch authentication

Source: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/mds9000/sw/5_2/configuration/guide/fabric/fabric/f_fabric_security.html

Topics

#SAN security#fabric services#switch authentication

Community Discussion

No community discussion yet for this question.

Full SG0-001 Practice