Based on the exhibit, what should be implemented to reduce the blast radius if a backup server is compromised later?
Backup job configuration: algorithm=AES-256-GCM key_file=/opt/backup/key.bin rotation=disabled same_key_for_all_sites=true backup_media copied to an offsite vault each night