ACFS Encryption True Statements

ASM backup, recovery and migration
Answer Correct answer: A, B, D — ACFS encryption rules dictate that file copies are only encrypted if from an encrypted directory, snapshots inherit encryption, and key length is specified during enablement.

Which three statements are true about ASM Cloud File System (ACFS) encryption? (Choose three.)

  1. A copy of an encrypted file is not encrypted unless it is created in an encrypted directory. Correct Answer
  2. An ACFS snapshot can be ACFS encrypted. Correct Answer
  3. acfsutil encr off can be run by an encryption manager who may not have system administrator privileges.
  4. acfsutil encr on can be used to specify the encryption key length for a directory or file. Correct Answer
  5. acfsutil encr init is used to establish role separation between encryption managers and encryption auditors.

Community Votes

ABD
67%
BDE
33%

67% of anonymous learners picked answer ABD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests detailed knowledge of ACFS encryption commands and properties, with a common trap involving the specific privileges required for encryption management vs auditing roles.

This page clarifies the correct behaviors of Oracle ACFS encryption, specifically addressing snapshot inheritance and role separation. It establishes that ABD are the true statements regarding encrypted file copies, snapshots, and key length specifications.

Many learners incorrectly select E instead of A, believing that acfsutil encr init handles file copy encryption rules or misinterpreting the role separation command's scope.

Community Discussion (5 comments)

jackhsu0704 👍 2
A. A copy of an encrypted file is not encrypted unless it is created in an encrypted directory. B. An ACFS snapshot can be ACFS encrypted. D. acfsutil encr on can be used to specify the encryption key length for a directory or file.
lcoleandro 👍 1 Selected: BDE
Correct Statements: B. ACFS snapshot can inherit encryption. D. acfsutil encr on specifies encryption key length. E. acfsutil encr init establishes role separation. Incorrect Statements: A. Copies of encrypted files remain encrypted. C. acfsutil encr off needs admin privileges.
217972f 👍 2
A: https://docs.oracle.com/en/database/oracle/oracle-database/19/ostmg/understand-acfs-admin.html#GUID-5591C710-D763-4F72-BB56-A1452CA6AAB2 B: https://docs.oracle.com/en/database/oracle/oracle-database/19/ostmg/understand-acfs-concepts.html#GUID-5A3EF695-A795-4FEA-8BE2-AF657BD2238C D: https://docs.oracle.com/en/database/oracle/oracle-database/19/ostmg/acfs-commands-encryption.html#GUID-778F5BA9-E70A-42B7-9266-D36C5C0BAB6A
wiprooracle 👍 2
looks to be ABD
krwi1 👍 2 Selected: ABD
E is wrong - there is no role separation with acfsutil encr init command.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because ACFS encryption is directory-based; files created in an unencrypted directory remain unencrypted even if they are copies of encrypted files. Option B is correct as ACFS snapshots inherit the encryption attributes of their source directory. Option D is correct because the acfsutil encr on command allows administrators to specify the encryption key length (e.g., AES192 or AES256) when enabling encryption.

Why the Other Options Are Wrong

Option C is incorrect because acfsutil encr off requires system administrator privileges, not just encryption manager privileges. Option E is incorrect because acfsutil encr init is used to initialize the encryption wallet and establish the infrastructure for role separation, but it does not 'establish role separation' in the sense of assigning users; rather, it prepares the environment where roles can be assigned. However, the statement is often considered false in exam contexts because the initialization itself doesn't perform the separation logic or assignment, and more importantly, Option A is a fundamental behavioral rule that is strictly true.

Community Comment Notes

Commenters like jackhsu0704 and krwi1 confirm that A, B, and D are the accepted answers. One commenter noted that 'E is wrong - there is no role separation with acfsutil encr init command,' highlighting the nuance that while the command sets up the environment, the statement is misleading compared to the factual accuracy of A.

Official Reference

Exam Strategy

Focus on understanding the difference between encryption managers and auditors, and how ACFS snapshot encryption inheritance works. Memorize the specific privileges required for each ACFS encryption command.

Frequently Asked Questions

Why is option E incorrect for ACFS encryption?

While acfsutil encr init initializes the encryption wallet, it does not directly establish role separation assignments. Role separation is configured via separate user assignments after initialization.

Does an ACFS snapshot retain encryption from its source?

Yes, ACFS snapshots inherit the encryption settings of the parent directory, ensuring data remains protected at rest in the snapshot.

More 1Z0-078 FAQ →

Related Analysis

← Back to 1Z0-078 Study Guide