CompTIA Security+ (SY0-701)Security ArchitectureMedium
A financial services firm requires that all customer data transmitted between its mobile app and backend API servers cannot be read even if intercepted on public Wi-Fi networks. Which control category directly addresses this requirement?
- AData at rest encryption
- BData in use encryption
- CData in transit encryption
- DData masking
Show answer & explanationAnswer & explanation
Correct answer: C. Data in transit encryption
Protecting data as it moves across a network, such as between a mobile app and API servers, is the definition of data-in-transit encryption, typically implemented via TLS.
Why the other options are wrong
- A. Data at rest protects stored data on disks or databases, not data actively moving across a network.
- B. Data in use protects data actively being processed in memory, not data traveling over Wi-Fi.
- D. Data masking obscures values within datasets but does not by itself protect network transmissions.
Data in Transit
Data actively moving across a network, protected primarily through encryption protocols like TLS or IPsec VPNs.
- TLS 1.2/1.3 commonly used for transit protection
- Prevents eavesdropping/man-in-the-middle attacks
- One of three data states: rest, transit, use
Memory trick: Rest=stored, Transit=moving, Use=processing.