Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A new web application is being developed that handles customer financial transactions. The development team is concerned about attackers intercepting sensitive data, such as credit card numbers, as it travels between the customer's browser and the web server. Which security control would be most effective in mitigating this specific threat?

  1. AEncryption in Transit
  2. BInput Validation
  3. CMulti-factor Authentication (MFA)
  4. DRegular Penetration Testing
Show answer & explanation

Correct answer: A. Encryption in Transit

Encryption in transit (e.g., using TLS/SSL) scrambles data as it travels across a network, making it unreadable to unauthorized parties if intercepted. This directly addresses the concern about attackers intercepting sensitive data between the browser and the server.

Why the other options are wrong

  • B. Input Validation prevents malicious data from being processed by the application, not interception during transmission.
  • C. MFA verifies user identity, but doesn't protect data while it's being transmitted.
  • D. Penetration testing identifies vulnerabilities but is not a control that actively protects data in transit.

Encryption in Transit

The process of encrypting data as it is transmitted over a network, ensuring that if intercepted, it remains unreadable and unintelligible to unauthorized parties.

  • Commonly implemented using TLS (Transport Layer Security) or SSL (Secure Sockets Layer).
  • Protects data from eavesdropping and man-in-the-middle attacks.
  • Essential for sensitive data communication over public networks like the internet.

Memory trick: Data is safe: At Rest, In Transit, In Use.

More Security Principles questions