Courseiva
SecurityhardMultiple SelectObjective-mapped

350-601 Security Practice Question

An engineer is deploying data encryption in a SAN environment. Which two methods provide at-rest encryption? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Self-encrypting drives (SED)

SED encrypts data on the drive; SAN array encryption encrypts data at the storage level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • MACsec encryption

    Why it's wrong here

    MACsec provides link-layer encryption, not at-rest.

  • FC-SP-2 encryption

    Why it's wrong here

    FC-SP-2 provides in-flight encryption for Fibre Channel.

  • IPsec encryption

    Why it's wrong here

    IPsec encrypts network traffic, not at-rest data.

  • Self-encrypting drives (SED)

    Why this is correct

    SED provides at-rest encryption on the drive.

  • EMC/NetApp at-rest encryption

    Why this is correct

    Storage arrays can provide at-rest encryption.

About these practice questions

Courseiva writes every 350-601 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.