ACFS Encryption True Statements
Which three statements are true about ASM Cloud File System (ACFS) encryption? (Choose three.)
Community Votes
67% of anonymous learners picked answer ABD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests detailed knowledge of ACFS encryption commands and properties, with a common trap involving the specific privileges required for encryption management vs auditing roles.
This page clarifies the correct behaviors of Oracle ACFS encryption, specifically addressing snapshot inheritance and role separation. It establishes that ABD are the true statements regarding encrypted file copies, snapshots, and key length specifications.
Many learners incorrectly select E instead of A, believing that acfsutil encr init handles file copy encryption rules or misinterpreting the role separation command's scope.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A is correct because ACFS encryption is directory-based; files created in an unencrypted directory remain unencrypted even if they are copies of encrypted files. Option B is correct as ACFS snapshots inherit the encryption attributes of their source directory. Option D is correct because theacfsutil encr on command allows administrators to specify the encryption key length (e.g., AES192 or AES256) when enabling encryption.Why the Other Options Are Wrong
Option C is incorrect becauseacfsutil encr off requires system administrator privileges, not just encryption manager privileges. Option E is incorrect because acfsutil encr init is used to initialize the encryption wallet and establish the infrastructure for role separation, but it does not 'establish role separation' in the sense of assigning users; rather, it prepares the environment where roles can be assigned. However, the statement is often considered false in exam contexts because the initialization itself doesn't perform the separation logic or assignment, and more importantly, Option A is a fundamental behavioral rule that is strictly true.Community Comment Notes
Commenters like jackhsu0704 and krwi1 confirm that A, B, and D are the accepted answers. One commenter noted that 'E is wrong - there is no role separation with acfsutil encr init command,' highlighting the nuance that while the command sets up the environment, the statement is misleading compared to the factual accuracy of A.Official Reference
Exam Strategy
Focus on understanding the difference between encryption managers and auditors, and how ACFS snapshot encryption inheritance works. Memorize the specific privileges required for each ACFS encryption command.
Frequently Asked Questions
Why is option E incorrect for ACFS encryption?
While acfsutil encr init initializes the encryption wallet, it does not directly establish role separation assignments. Role separation is configured via separate user assignments after initialization.
Does an ACFS snapshot retain encryption from its source?
Yes, ACFS snapshots inherit the encryption settings of the parent directory, ensuring data remains protected at rest in the snapshot.