CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium
A healthcare provider is upgrading its patient management system. The new system will allow authorized medical staff to access patient records from various remote clinics over a public network. Due to HIPAA regulations, all data exchanged between the remote clinics and the central database must be protected from eavesdropping. Which protocol or technology is MOST effective for securing this data in transit?
- ASecure Shell (SSH)
- BTransport Layer Security (TLS)
- CLightweight Directory Access Protocol (LDAP)
- DFile Transfer Protocol (FTP)
Show answer & explanationAnswer & explanation
Correct answer: B. Transport Layer Security (TLS)
Transport Layer Security (TLS) is the successor to SSL and is widely used to encrypt data in transit over public networks. It provides secure communication between clients (remote clinics) and servers (central database), protecting sensitive patient data from eavesdropping as required by HIPAA.
Why the other options are wrong
- A. SSH is primarily used for secure remote command-line access or tunneling, not typically for general database client-server communication.
- C. LDAP is used for directory services and authentication, not primarily for encrypting general database traffic.
- D. FTP is an insecure protocol for file transfer and does not provide encryption for data in transit.
Encryption in Transit (TLS)
The process of encrypting data as it travels across a network, protecting it from interception and eavesdropping during transmission.
- Uses protocols like TLS/SSL for secure communication.
- Protects data from client to server and vice-versa.
- Essential for public networks and regulatory compliance (e.g., HIPAA, GDPR).
Memory trick: Data in transit needs a secure tunnel to fly through.