A new tenant is onboarded on a Data Domain system with Secure Multi-Tenancy enabled. The engineer must ensure all of that tenant’s backup data, quotas, and administrative scope remain isolated inside the tenant context. What should the engineer do?
Select an answer to reveal the explanation.
Short Explanation
Think of a tenant MTree as a fenced yard: once you assign the MTree to the tenant, everything inside it belongs to that tenant’s world. You don’t get isolation by just turning on a backup protocol or a lock; you get it by putting the storage path inside the tenant context. Miss that assignment, and the data is still floating in the shared system.
Full Explanation
Secure Multi-Tenancy isolates data by binding storage resources, represented by MTrees, to a tenant. When an MTree is assigned to a tenant, the tenant namespace, capacity accounting, and administrative delegation are evaluated inside that tenant context, so backup clients and tenant administrators cannot traverse outside the assigned scope. This is how a policy applied to a new tenant becomes effective: the storage path must be placed inside the tenant, not merely configured with a feature. DD Boost enables application-integrated backup and can be used within a tenant, but it does not by itself create tenant isolation or change ownership of the storage path. A retention lock protects data from deletion or modification for a defined period, yet it does not assign the MTree to a tenant or control administrative visibility. A replication context defines asynchronous data protection between systems and can be scoped to tenants, but it is a disaster-recovery construct rather than the mechanism that places data inside the tenant boundary. Exam caveat: distinguish tenant membership from tenant capabilities; a feature can be enabled inside a tenant only after the tenant already owns the relevant MTree. Operational check: after tenant creation, verify the intended MTree appears under that tenant storage allocation and that a tenant administrator cannot list or access MTrees outside it.