Acceptance testing of a new Data Domain turns up a finding from the security team: the backup path exported over NFS is mountable by every server on the roomy campus subnet, not just the two media servers named in the design. The engineer is baffled, because the NFS service was enabled exactly as the connectivity runbook says. What did the connectivity configuration miss?
Select an answer to reveal the explanation.
Short Explanation
A file share you can open without a key isn't a share, it's a public drop box. Exporting a backup path also means declaring who may mount it, allowed hosts on the export plus dedicated credentials, not just flipping NFS on. If the whole campus can mount your backup target, then your backup target has become the campus attack surface.
Full Explanation
Enabling a file service is only half of file connectivity; the other half is restricting it. On the appliance, NFS exports are paired with an allowed client list naming the specific hosts or networks permitted to mount each path, and the design pairs that with dedicated access users and firewall scoping, so a path intended for two media servers is unusable from the rest of the subnet even if a campus host guesses the export name. A retention lock governs whether written data can be altered or deleted, which is a different axis entirely; immutability does not stop a stranger from mounting a path and writing or reading within its permissions. Handing mount control to switch port security misunderstands the enforcement point, since the appliance itself decides which clients it serves, and network controls are complementary hardening rather than a substitute for the export list. The Kerberos-as-default claim inverts reality: classic NFS trust is host-based and quiet about identity, so authentication must be deliberately designed and deployed, not assumed from a service-status line. Exam caveat: record the allowed-client list in the as-built and reconcile it with the firewall ticket. Operational check: attempt a mount from an unauthorized host and confirm refusal, then mount from each authorized media server and confirm success.