During the security requirement review, the customer's security team demands that the encryption keys protecting backup data at rest be held in their own external key manager rather than on the appliance. What is the correct pre-deployment action for the engineer?
Select an answer to reveal the explanation.
Short Explanation
Think of external key management as keeping your safe's keys at the bank instead of the desk drawer—great control, but you'd better prove the bank is open before you lock anything away. Your job now is planning the KMIP integration and verifying the key manager is reachable and redundant, then enabling encryption on top of that. Bolt it on later without those checks and your backups become very expensive paperweights.
Full Explanation
Data Domain supports encryption of data at rest with keys held either locally on the system or in an external key manager reached over the KMIP protocol; when a customer mandates their own key custody, the pre-deployment task is to design and validate that integration—network reachability, certificate exchange, and enough redundant key servers that the system can always retrieve its keys to access the encoded pool. Treating the demand as a note for later with no prerequisites fails by concept because an encrypted storage pool depends on key availability, so an unreachable key manager becomes a data-availability outage that must be engineered away before encryption goes live. Declining the requirement fails because external key management is a supported design, not a platform limitation. Buying a dedicated key appliance fails the requirement's own logic, because key custody belongs to the customer's existing KMIP service and the demand is about who holds keys, not about physically splitting hardware. Exam caveat: data encoded under external keys cannot be read if the key service is permanently lost, so the design must state key recovery and backup procedures. Operational check: test connectivity to the KMIP endpoint, validate certificates and key-server failover, and record security sign-off before encryption enablement is scheduled.