CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
A company's cloud-hosted web application transmits customer form submissions over the public internet to a backend database. To ensure this data cannot be intercepted and read by an attacker performing a man-in-the-middle attack during transmission, which encryption approach must be implemented?
- AFull-disk encryption on the database server
- BEncryption of data in transit using TLS
- CEncryption of data in use within application memory
- DFile-level encryption of stored backups
Show answer & explanationAnswer & explanation
Correct answer: B. Encryption of data in transit using TLS
Data moving across a network, such as customer form submissions traveling to a backend database, must be protected with encryption in transit (typically TLS), which prevents interception and reading by attackers during transmission.
Why the other options are wrong
- A. Full-disk encryption protects stored data on the server, not data actively moving across the network.
- C. Encryption of data in use protects data being actively processed in memory, not during network transmission.
- D. File-level backup encryption protects stored archive data, not the live transmission of form data.
Encryption in Transit
The protection of data as it moves across a network between systems, typically implemented using protocols like TLS/SSL to prevent interception.
- Protects against man-in-the-middle attacks
- Distinct from encryption at rest (stored data) and in use (processed data)
- TLS is the most common protocol used for data in transit
Memory trick: In transit = data 'on the highway,' needs a TLS armored truck