350-601 Security Practice Question
An engineer is deploying data encryption in a SAN environment. Which two methods provide at-rest encryption? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Self-encrypting drives (SED)
SED encrypts data on the drive; SAN array encryption encrypts data at the storage level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACsec encryption
Why it's wrong here
MACsec provides link-layer encryption, not at-rest.
- ✗
FC-SP-2 encryption
Why it's wrong here
FC-SP-2 provides in-flight encryption for Fibre Channel.
- ✗
IPsec encryption
Why it's wrong here
IPsec encrypts network traffic, not at-rest data.
- ✓
Self-encrypting drives (SED)
Why this is correct
SED provides at-rest encryption on the drive.
- ✓
EMC/NetApp at-rest encryption
Why this is correct
Storage arrays can provide at-rest encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-601 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.