Yeah, "security key-manager setup" command will generate two keys.
you can choose and assign any one of the key for "data-key" and the other for "fips-key", even you can use the exact same key for both of them.
or you can just use one key for "data-key" and don't even assign anything for "fips-key"
Its totally depends on your organization's encryption requirements, ill recommend you read the guide, I believe it have some details regarding this.
Also be aware about the procudure of how to replace the NSE Disks after a disk failure.
robin.