A Data Domain system uses a local key manager for encryption. The only escrow copy of the master key is on one administrator's laptop. Before relying on this configuration, what should be addressed?
Select an answer to reveal the explanation.
Short Explanation
Think of the key escrow like the only house key your tenant can use. If it lives on one laptop, you're one crash or lost admin away from encrypted data that can't be opened. Build a real custody process so the key survives the laptop.
Full Explanation
Local key manager custody means the Data Domain system is responsible for the encryption keys used to protect stored data. If the only escrow copy is on one administrator's laptop, the organization has a single point of failure: laptop loss, theft, disk failure, or admin departure can make encrypted data unrecoverable by design. The correct response is an independent escrow or backup-of-record process, with controlled storage, separation of duties, documented recovery steps, and periodic testing. Keeping the laptop powered on and connected to the network does not create redundancy or governance; it only preserves availability of one copy. Assigning the same administrator to manage all backup encryption keys increases risk by concentrating control and violating separation of duties. Replacing the local key manager with a cloud key manager is an architecture change that may not be supported or desired in the scenario, and it does not address the immediate custody gap unless properly designed and validated. Exam caveat: on the exam, choose the answer that protects key recoverability without inventing an unsupported migration. Operational check: place the escrow copy in a separate approved repository, record custodians and access approvals, and rehearse key recovery before production reliance.