An application can reach the Data Domain either over plain NFS across a shared campus network that every department traverses, or over TLS-protected object or FTPS paths on the same network. The storage team wants to pick whichever option needs the least configuration. What should drive that protocol decision?
Select an answer to reveal the explanation.
Short Explanation
Read the fine print, because both will work isn't both are equal. Plain NFS ships your backups in the clear across a campus network every department can sniff, while FTPS and S3 wrap the session in TLS from the start. When the wire isn't yours alone, the protocol's encryption behavior is a design input, not a config-avoidance contest.
Full Explanation
The security profile of an access path is a property of the protocol itself: a plain NFS export transmits payload without per-session encryption, whereas FTPS and S3 endpoints require TLS, giving confidentiality and integrity of data in transit, which matters whenever frames cross segments other teams control, since capture on a shared fabric is a practical threat. Protocol selection therefore balances capability, throughput, and network trust, and the least-configuration tiebreaker quietly deletes the decisive input. Identical-transport-layer-encryption is a myth, since TCP carries bytes, not confidentiality, and nothing wraps a plain NFS payload automatically. The blanket NFS-wins-on-shared-networks rule inverts the risk, because although directory services and SMB deployments vary in their encryption options, claiming file protocols encrypt by default misstates typical export behavior and is precisely wrong on a network every department can read. Purchasing a third-party encryptor is unnecessary when the target already offers natively encrypted ingest paths, duplicating work the appliance already performs natively. Exam caveat: on a genuinely isolated, controlled backup fabric, an unencrypted file path can be a deliberate, documented decision, but it must be made, not defaulted into. Operational check: verify the chosen service enforces TLS, with the non-secure option rejected, and record how that was proven for the shared network path.