CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a secure communication channel for a critical real-time financial transaction system that spans multiple geographical locations. The primary requirements are strong authentication of communicating parties, data confidentiality, and data integrity over an untrusted network. Which of the following protocols is BEST suited to meet these requirements?
- AIPsec (Internet Protocol Security)
- BTLS (Transport Layer Security)
- CSSH (Secure Shell)
- DHTTPS (Hypertext Transfer Protocol Secure)
Show answer & explanationAnswer & explanation
Correct answer: A. IPsec (Internet Protocol Security)
IPsec operates at the network layer, providing comprehensive security services including strong authentication, confidentiality, and integrity for all traffic between two endpoints, making it ideal for securing entire communication channels across untrusted networks.
Why the other options are wrong
- B. TLS primarily secures communication at the transport layer for specific applications, not the entire network channel.
- C. SSH is primarily used for secure remote access and tunneling, not for securing general network traffic between systems.
- D. HTTPS secures web traffic (HTTP over TLS) at the application layer, which is too high-level for securing a general financial transaction system's network channel.
IPsec (Internet Protocol Security)
A suite of protocols for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session.
- Operates at the network layer (Layer 3 of OSI model).
- Provides confidentiality, integrity, and authenticity.
- Commonly used to create VPNs and secure router-to-router communication.
Memory trick: IPsec ensures my network packets are always 'IP-Safe' and sound.