An agency is designing its secure private cloud on VMware Cloud Foundation with the following requirements:* Strict data segregation between the management and workload domains.* Company policy prevents using vSAN as a storage solution.* Data encryption at rest is mandatory for both the management and workload domains.* Data encryption in transit is mandatory for the workload domains.* Data-at-rest encryption must be performed by the storage array and not rely on VMware native or vSAN- specific mechanisms.* Allow for automated VM placement, operational integrity with VCF Operations, and assurance that file- based workloads scale efficiently.Which storage architecture fulfills these technical and regulatory requirements?
A. eploy metro clusters backed by Self-Encrypting Disk (SED) using iSCSI for both domains and configure encrypted VLANs for data-in-transit between VCF Operations and hosts
B. nable VMware VM-level encryption using vSphere Native Key Provider (NKP) on local VMFS disks for all environments, implementing manual file workload allocation through generic SMB shares
C. onfigure dedicated VMFS datastores on separate Fibre Channel arrays for management and workloads, with array-based encryption enabled and SPBM storage policies assigned
D. reate a unified NAS platform offering both NFS and SMB exports shared across management and workload domains, then enable application-level encryption for sensitive workloads and restrict access via firewall rules