Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy

An organization is deploying a new web application that will handle sensitive customer payment information. To comply with PCI DSS requirements and ensure the integrity and confidentiality of data in transit, which cryptographic protocol should be implemented?

  1. AHTTP (Hypertext Transfer Protocol)
  2. BSNMP (Simple Network Management Protocol)
  3. CFTP (File Transfer Protocol)
  4. DTLS (Transport Layer Security)
Show answer & explanation

Correct answer: D. TLS (Transport Layer Security)

TLS (Transport Layer Security) is the standard cryptographic protocol used to secure communications over a computer network, providing privacy and data integrity between two communicating computer applications. It is essential for protecting sensitive data like payment information in transit and is explicitly required by PCI DSS for web transactions.

Why the other options are wrong

  • A. HTTP is an unencrypted protocol for web communication; it does not provide security for sensitive information without TLS.
  • B. SNMP is used for network device management and monitoring; it is not a protocol for securing general web application traffic.
  • C. FTP is an unencrypted protocol for file transfer and does not provide confidentiality or integrity for sensitive data.

TLS (Transport Layer Security)

A cryptographic protocol designed to provide communication security over a computer network, commonly used for securing web browsing, email, instant messaging, and other data transfers.

  • Successor to SSL (Secure Sockets Layer).
  • Provides confidentiality, integrity, and authentication.
  • Widely used with HTTPS to secure web traffic.

Memory trick: Secure Transmissions Lock Sensitive Data.

More Security Concepts questions