The security team runs a default-deny firewall and asks the engineer to produce, as one deliverable, everything that must be opened for the new Data Domain system. What belongs in that deliverable, and why is it a first-week item?
Select an answer to reveal the explanation.
Short Explanation
A default-deny firewall is a bouncer with a strict list: unless your guests are named, nobody gets in. You hand security a port list per protocol you actually planned—management, each backup protocol, replication—and you do it first, because nothing installs, integrates, or replicates until that conversation ends well. This is the requirement that gates all the others.
Full Explanation
A default-deny firewall is an unmet dependency for every subsequent task, so the ports deliverable is a first-week item: it should enumerate management planes such as the web console and SSH, each backup protocol selected during design—DD Boost or OpenStorage, NFS, CIFS/SMB, NDMP—and the replication path to the DR system, with traffic directions and source and destination zones. Serial numbers fail as a concept because firewall rules authorize flows between endpoints, not hardware identities, and a serial number answers none of the security team's questions. A blanket VLAN-to-VLAN opening fails the least-privilege model the security team exists to enforce and will not pass their review. Listing only the management port fails because day-one usefulness includes backup data protocols and replication traffic; a reachable console on an isolated appliance delivers no protected data. Exam caveat: exact port numbers belong in the official reference documentation for the installed DD OS version rather than in anyone's memory. Operational check: run the matrix through the security team's approval process and hold confirmed rule tickets for each flow before the installation date.