CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium

A healthcare organization is developing a new patient record system. Due to strict HIPAA compliance requirements, all patient health information (PHI) must be protected during transmission between the web application servers and the database servers. Which of the following protocols is best suited to ensure data confidentiality and integrity during this transit?

  1. ATLS
  2. BSMTP
  3. CHTTP
  4. DFTP
Show answer & explanation

Correct answer: A. TLS

TLS (Transport Layer Security) is the standard cryptographic protocol designed to provide secure communication over a computer network by ensuring data confidentiality, integrity, and authenticity between communicating applications, making it ideal for protecting PHI in transit.

Why the other options are wrong

  • B. SMTP (Simple Mail Transfer Protocol) is for email transmission and is not designed for securing general application-to-database communication.
  • C. HTTP (Hypertext Transfer Protocol) is unencrypted and does not provide confidentiality or integrity for data in transit.
  • D. FTP (File Transfer Protocol) is primarily for file transfer and typically operates without encryption, making it unsuitable for sensitive data unless secured with TLS (FTPS).

Encryption in Transit

The process of encoding data as it moves across a network to protect it from interception and unauthorized access.

  • Protects data during network communication.
  • Commonly uses protocols like TLS/SSL or IPsec.
  • Ensures confidentiality and integrity of transmitted data.

Memory trick: Data traveling needs a safe tunnel, not an open road.

More Data and Database Security questions