A managed service provider and an internal department are to share one Data Domain. The compliance rule is explicit: neither party's operators may see, address, or administer the other party's backups or configuration. The administrator asks whether dedicated MTrees with carefully restricted users already satisfy that requirement. What does the scenario actually call for?
Select an answer to reveal the explanation.
Short Explanation
Separate folders are a fence between backyards when two organizations share one house, because anyone with the master key walks everywhere. Secure Multi-Tenancy is what your scenario's wording demands: its own management context, its own virtual storage, and literally no visibility across tenants. Read requirements like a tester, not a wishful thinker; the words see, address, and administer are what change your design.
Full Explanation
The requirement's wording is decisive: operators on both sides hold administrative roles, and administration is exactly what MTree permissions cannot isolate, because tenant administrators landing on a single shared operating system would still traverse the same shell, configuration, and device space regardless of folder grants. Secure Multi-Tenancy addresses that directly by partitioning one physical system into tenant contexts, each with its own administrators, its own virtual storage resources and its own view of configuration, while the system-level administrator manages the envelope, delivering the no-crossing compliance rule inside one chassis. The MTree-plus-audits answer substitutes process for architecture: audits detect drift after the fact and do nothing about an administrative account's inherent reach. Insisting on physical separation is too strict as a rule, since documented multi-tenancy exists for precisely this consolidation case, even though buying a second box remains a budget decision rather than a technical necessity. Guest shares behind firewalls abandon both least privilege and any management isolation, anonymous access being the opposite of the accountability the rule demands. Exam caveat: SMTX setup and licensing are project work in themselves, and maintenance windows must be coordinated across tenants. Operational check: as each tenant's administrator, list storage and configuration surfaces and confirm the other tenant is entirely invisible.