QuestionQ108

Installing, Configuring, and Setup

A vSAN administrator has been asked to encrypt all data and metadata traffic across every host in a vSAN cluster.

Which action is required to provide this level of encryption?

  • A Deploy KMS server, and enable vSAN Data at Rest and In-Transit encryption at the host level
  • B Enable vSAN Data In-Transit encryption at the cluster level; no KMS or NKP is required
  • C Enable vSAN Cluster level encryption via Storage Policy; no KMS or NKP is required
  • D Deploy NKP server, and enable vSAN Data at Rest encryption at the cluster level
Explanation

vSAN Data-In-Transit Encryption encrypts the data and metadata transmitted among hosts in a vSAN cluster. It is enabled at the cluster level and does not require a KMS or Native Key Provider; key management is required for vSAN data-at-rest encryption instead.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!