NCP Exam QuestionsBrowse all questions from this exam

NCP Exam - Question 113


An administrator is working with sensitive data and wants to encrypt that data by Nutanix Software Encryption.

Which three types of information and components are required to enable this configuration? (Choose three.)

Show Answer
Correct Answer: ABDE

To enable Nutanix Software Encryption, you need a Key Management Server (KMS) to manage the encryption keys, a Root Certificate Authority (CA) to validate certificates, and a KMS Certificate to establish trust between the KMS and the Nutanix environment. These components ensure that encryption keys are securely managed and the integrity of the system is maintained. Self-Encryption Drives (SED) are related to hardware-based encryption, not software encryption, and a signed certificate for each CVM is not required for this configuration.

Discussion

4 comments
Sign in to comment
QuietmanOptions: ABD
Sep 24, 2021

Should be ABD: you need KMS, KMS cert, and CA to sign it. You don't need a cert for each CVM (C), and SEDs are the hardware-based encryption concept. Ref.: https://portal.nutanix.com/page/documents/details?targetId=Nutanix-Security-Guide-v6_0:wc-security-data-encryption-aos-wc-c.html

sanvalOptions: ABD
Jan 8, 2022

no need of cert for CVM

HealthyGeneralOptions: ABD
Mar 26, 2022

ABD! E is incorrect because SEDs are hardware, whilst question states software encryption.

adrybngOptions: ABD
Jan 27, 2022

Should be ABD