Professional Architect - 4 - Cloud Storage
Professional Architect - 4 - Cloud Storage
Study Guide
4.1 File Storage Capabilities and • Define the options and capabilities of classic storage on IBM
Options on IBM Cloud Cloud
4.2 Block Storage Capabilities and • Define the capabilities and options of classic block storage
Options on IBM Cloud
• Define the options and capabilities of classic file storage
4.3 Object Storage Capabilities and • Identify VPC block storage and its capabilities
Options on IBM Cloud
• Distinguish the differences between boot volumes and data
volumes of VPC block storage
• List the data encryption options of VPC block storage
• Identify what Key Protect and Hyper Protect Crypto Services are
and why they are important
• Identify storage classes, resiliency options, and
review encrypting data
• Identify object storage and retention policies
• Define Aspera high-speed transfer and large object storage
• Determine your responsibilities when using IBM Cloud Object
Storage
2 © Copyright IBM Corp. 2023
IBM Cloud Storage Options
Study Guide
In File Storage Capabilities and Options on IBM Cloud, the subject matter:
• Focuses on IBM Cloud File storage.
• Highlights best use cases for file storage options.
• Emphasizes options and capabilities of classic file storage.
• Provides IBM Cloud classic storage options and capabilities.
Lessons
Objectives
• Define the options and capabilities of classic storage on IBM Cloud
• Define the capabilities and options of classic block storage
• Define the options and capabilities of classic file storage
Features include:
Snapshots
• Represents a volume's contents at a particular point in time and considered the first line of defense
for data protection
• Snapshots can be scheduled hourly, daily, or weekly to meet application business requirements
Data Replication
Encryption-at-rest
• With provider-managed encryption, file storage that is provisioned with either Endurance or
Performance options is secured by default at no additional cost
Adjustable IOPS
• Two options when choosing the IOPS needed for a workload: Endurance & Performance Storage
• Once a user chooses a tiered or customized option, there is no ability to switch between the two
Expandable Storage
Question 1.
Which statement is true regarding snapshots storage volume on classic storage on
IBM Cloud?
Question 2.
Question 3.
A. When adjusting IOPS, there will be a very small outage or lack of access
to the storage
B. In order to adjust IOPS of an already deployed storage, a duplicate must
be created or manually copied to new storage
C. When adjusting the IOPS, the replica must also be manually adjusted
D. Once a user chooses a tiered or customized option, there is no ability to
switch between Endurance and Performance
Question 4.
In Block Storage Capabilities and Options on IBM Cloud, the subject matter:
• Focuses on block storage for IBM Cloud virtual private cloud (VPC) and its capabilities.
• Highlights the boot and data volumes of block storage for VPC.
• Emphasizes volume sizing, Input/Output Operations per Second (IOPS) profiles, and tiers.
• Provides data encryption options for block storage for VPC.
Lessons
Objectives
• Identify VPC block storage and its capabilities
• Distinguish the differences between boot volumes and data volumes of VPC block storage
• List the data encryption options of VPC block storage
Block storage for VPC offers block-level volumes that are attached to an instance as a boot volume
when the instance is created or attached as secondary data volumes. Up to 300 block storage
volumes per account in a region can be configured. Each instance can have up to 12 block storage
volumes attached to it, which can be added one at a time.
IOPS Profiles
When block storage for VPC data volumes are provisioned using the IBM Cloud Console, users specify
an IOPS profile that best meets their storage read/write requirements. IOPS defines the maximum
number of input and output operations per second the storage is capable of, or in other words, the
overall speed of the storage.
Question 1.
Which of the following is suitable for an application that is running in VPC and
requires 300 GB of high performance, encrypted storage?
In Object Storage Capabilities and Options on IBM Cloud, the subject matter:
• Focuses on storage classes, resiliency options, and encrypting data.
• Highlights IBM Cloud Object Storage.
• Emphasizes the use of encryption keys for high security, including what Key Protect and Hyper
Protect Crypto Services have to offer.
• Provides information on how to use Aspera high-speed transfer, how to store large objects, and both
the client's and IBM's responsibilities when using IBM Cloud Object Storage.
Lessons
Objectives
• Identify what Key Protect and Hyper Protect Crypto Services are and why they are important
• Identify storage classes, resiliency options, and review encrypting data
• Identify object storage and retention policies
• Define Aspera high-speed transfer and large object storage
• Determine your responsibilities when using IBM Cloud Object Storage
Resiliency Options
IBM Cloud Object Storage offers worldwide locations for data storage through three resiliency options.
Cross Region
Data is stored across three regions within a geography for highest availability and resiliency.
Regional
Data is stored in multiple data center facilities within a single geographic region for best
availability and performance.
Data Encryption
IBM Cloud Object Storage provides several options to encrypt data. By default, all objects that are stored in
IBM Cloud Object Storage are encrypted by using randomly generated keys and an all-or-nothing-transform
(AONT). Clients can manage their keys manually on a per-object basis by providing their own encryption
keys - referred to as Server-Side Encryption with Customer-Provided Keys (SSE-C).
The following services, IBM Key Protect for IBM Cloud and IBM Cloud Hyper Protect Crypto Services,
could be used with IBM Cloud Object Storage, as well as many IBM Cloud services.
IBM Key Protect for IBM Cloud IBM Cloud Hyper Protect Crypto Services
• Provisions encrypted keys for apps across IBM • A dedicated key management service and
Cloud services Hardware Security Module (HSM)
• Keys are secured by the Federal Information • Provides clients with the Keep Your Own Key
Processing Standard Publication (FIPS) 140-2 (KYOK) capability for cloud data encryption
Level 3
• Built on FIPS 140-2 Level 4-certified hardware
• Ability to Bring Your Own Key (BYOK) for exclusive control of their encryption keys
Benefits:
• Get faster transfer speeds
• Transfer large object uploads over 200 MB in the console and 1 GB by using an SDK or library
• Upload entire folders of any type of data, such as multimedia files, disk images, and any other
structured or unstructured data
• Customize transfer speeds and default preferences
• View, pause, resume, or cancel transfers independently
Question 1.
A client's stored data needs to be highly available to all the requested regions in
the EU and US. They have a solution where IBM Cloud Object Storage is adopted
to store data objects between several services distributed in several regions.
Which resiliency option will support that case?
A. High availability
B. Regional
C. Single site
D. Cross region
Question 2.
What method should be used to upload data objects for a client using a solution
where data objects must be uploaded regularly into IBM Cloud Object Storage and
the minimum size of the transferred objects is 500 MB?
A. FTP
B. Box REST API
C. Aspera using SDKs
D. SCP
Question 3.
All objects that are stored in IBM Cloud Object Storage are encrypted by default
using randomly generated keys. In some situations, workloads need to be
encrypted using provided client data encryption keys. The keys can be managed
using ______.
Question 4.
A client is using IBM Cloud Object Storage as a repository for video images
uploaded to their social media application. What service can the client use to
enable high-speed data transfer for those videos between their web servers and
IBM Cloud Object Storage?
Question 5.
What is the best storage option for a client that has 18 TB of archived data stored
in IBM Cloud that must be available across multiple availability zones to achieve
fault tolerance and high availability?
Question 6.
An application deployed on a multizone Red Hat OpenShift cluster requires a
multizone, highly available and highly resilient ReadWriteMany storage to store
uploaded images and document files, mainly unstructured data. The IBM Cloud
________ storage type will serve this purpose.
A. VPC Block
B. Classic File
C. IBM Cloud Object
D. IBM Cloud NoSQL Database service
Acronyms
PV Persistent Volume