During a post-deployment review, the customer adds an expansion shelf to a Data Domain system that already has encryption at rest enabled. They ask whether the new shelf’s disks must be encrypted separately before backup data can use them. What should you tell them?
Select an answer to reveal the explanation.
Short Explanation
Think of encryption like a fence around your backyard: once the yard is protected, adding a new patch of grass doesn't mean you rebuild the fence. If the Data Domain system already has encryption at rest turned on, expansion capacity inherits that protection automatically. The trap is treating each shelf like a separate system that needs its own switch.
Full Explanation
Data Domain encryption at rest is implemented as a system-level property, not a per-shelf toggle. Once the system is configured with encryption enabled, the active encryption state governs the entire managed file system. When an expansion shelf is later added to that same system, its disks become part of the same protected storage pool and inherit the existing at-rest protection without a separate encryption operation. The idea that each shelf needs its own encryption key or activation is incorrect because expansion shelves are not independent Data Domain systems; they are capacity extensions managed by the same DD OS instance. The idea that a shelf must be present before encryption is first enabled is also incorrect because inheritance depends on the system's current encrypted state, not on when the hardware was first installed. The idea that external key management changes this behavior is incorrect because external key management changes how keys are stored, accessed, or rotated, not whether newly added capacity falls under the system's encryption policy. Exam caveat: Focus on whether encryption is enabled for the Data Domain system as a whole, not on whether each physical shelf has a separate encryption setting. Operational check: After adding the shelf and expanding the file system, confirm the system remains in an encrypted-at-rest state and that the new capacity is visible as part of the same protected file system.