CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard

A company's cloud-hosted web application transmits customer form submissions over the public internet to a backend database. To ensure this data cannot be intercepted and read by an attacker performing a man-in-the-middle attack during transmission, which encryption approach must be implemented?

  1. AFull-disk encryption on the database server
  2. BEncryption of data in transit using TLS
  3. CEncryption of data in use within application memory
  4. DFile-level encryption of stored backups
Show answer & explanation

Correct answer: B. Encryption of data in transit using TLS

Data moving across a network, such as customer form submissions traveling to a backend database, must be protected with encryption in transit (typically TLS), which prevents interception and reading by attackers during transmission.

Why the other options are wrong

  • A. Full-disk encryption protects stored data on the server, not data actively moving across the network.
  • C. Encryption of data in use protects data being actively processed in memory, not during network transmission.
  • D. File-level backup encryption protects stored archive data, not the live transmission of form data.

Encryption in Transit

The protection of data as it moves across a network between systems, typically implemented using protocols like TLS/SSL to prevent interception.

  • Protects against man-in-the-middle attacks
  • Distinct from encryption at rest (stored data) and in use (processed data)
  • TLS is the most common protocol used for data in transit

Memory trick: In transit = data 'on the highway,' needs a TLS armored truck

More Governance, Risk, Compliance and Security questions