How can you protect data access in transit between clients and ONTAP?

Prepare for the NetApp Certified Storage Installation Engineer Test. Study with flashcards and multiple choice questions featuring hints and explanations. Ace your certification!

Multiple Choice

How can you protect data access in transit between clients and ONTAP?

Explanation:
Protecting data as it moves between clients and ONTAP requires encryption and authenticated channels throughout the path. Use secure management channels like HTTPS for ONTAP management and SSH for administrative access, so credentials and commands aren’t exposed. For the actual file access paths, turn on protocol-level encryption: SMB encryption on SMB, and Kerberos-based authentication for NFS (which can provide strong authentication and, with proper configuration, encryption for in-transit data). Layer in network protections such as firewalls, segmentation, IPsec, or VPNs to limit exposure and ensure traffic travels over trusted paths. This combination delivers confidentiality, integrity, and proper authentication for data in transit. Relying on plain HTTP provides no encryption, SMB1 is outdated and lacks robust protection, and disk encryption protects only data at rest, not data in transit.

Protecting data as it moves between clients and ONTAP requires encryption and authenticated channels throughout the path. Use secure management channels like HTTPS for ONTAP management and SSH for administrative access, so credentials and commands aren’t exposed. For the actual file access paths, turn on protocol-level encryption: SMB encryption on SMB, and Kerberos-based authentication for NFS (which can provide strong authentication and, with proper configuration, encryption for in-transit data). Layer in network protections such as firewalls, segmentation, IPsec, or VPNs to limit exposure and ensure traffic travels over trusted paths. This combination delivers confidentiality, integrity, and proper authentication for data in transit. Relying on plain HTTP provides no encryption, SMB1 is outdated and lacks robust protection, and disk encryption protects only data at rest, not data in transit.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy