Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy
An organization is deploying a new web application that will handle sensitive customer data. The security team wants to ensure that all communication between the client's browser and the web server is encrypted and that the server's identity is authenticated. Which protocol should be implemented to achieve these security goals?
- ATLS (Transport Layer Security)
- BFTP (File Transfer Protocol)
- CHTTP (Hypertext Transfer Protocol)
- DDNS (Domain Name System)
Show answer & explanationAnswer & explanation
Correct answer: A. TLS (Transport Layer Security)
TLS (Transport Layer Security) is the protocol that provides encryption and authentication for communications over a computer network. It is used to secure web traffic (HTTPS), ensuring data confidentiality and integrity, and authenticating the server to the client.
Why the other options are wrong
- B. FTP is for file transfer and does not inherently provide encryption or authentication.
- C. HTTP is the basic web protocol and does not provide encryption or server authentication on its own.
- D. DNS translates domain names to IP addresses and is not for securing application communication.
TLS (Transport Layer Security)
A cryptographic protocol designed to provide communication security over a computer network. It encrypts the segments of network connections at the Application Layer and is widely used for secure web browsing (HTTPS), email, instant messaging, and other data transfers.
- Successor to SSL (Secure Sockets Layer).
- Provides confidentiality (encryption), integrity (tamper detection), and authenticity (server identity).
- Uses asymmetric and symmetric cryptography, along with digital certificates.
Memory trick: TLS is like a secure tunnel for your web traffic, keeping everything private and verified.