CompTIA Security+ (SY0-701)Security ArchitectureMedium

A financial services firm requires that all customer data transmitted between its mobile app and backend API servers cannot be read even if intercepted on public Wi-Fi networks. Which control category directly addresses this requirement?

  1. AData at rest encryption
  2. BData in use encryption
  3. CData in transit encryption
  4. DData masking
Show answer & explanation

Correct answer: C. Data in transit encryption

Protecting data as it moves across a network, such as between a mobile app and API servers, is the definition of data-in-transit encryption, typically implemented via TLS.

Why the other options are wrong

  • A. Data at rest protects stored data on disks or databases, not data actively moving across a network.
  • B. Data in use protects data actively being processed in memory, not data traveling over Wi-Fi.
  • D. Data masking obscures values within datasets but does not by itself protect network transmissions.

Data in Transit

Data actively moving across a network, protected primarily through encryption protocols like TLS or IPsec VPNs.

  • TLS 1.2/1.3 commonly used for transit protection
  • Prevents eavesdropping/man-in-the-middle attacks
  • One of three data states: rest, transit, use

Memory trick: Rest=stored, Transit=moving, Use=processing.

More Security Architecture questions