Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security team is deploying a new web application that will handle sensitive customer payment information. To protect data in transit, they decide to implement strong encryption and ensure that all communication between the client's browser and the web server is secure. Which cryptographic protocol is most suitable for this purpose?
- ASMTP (Simple Mail Transfer Protocol)
- BSNMP (Simple Network Management Protocol)
- CFTP (File Transfer Protocol)
- DTLS (Transport Layer Security)
Show answer & explanationAnswer & explanation
Correct answer: D. TLS (Transport Layer Security)
TLS (Transport Layer Security) is the standard cryptographic protocol used to provide secure communication over a computer network, particularly for web browsing (HTTPS). It ensures confidentiality, integrity, and authenticity of data in transit.
Why the other options are wrong
- A. SMTP is for email transfer and does not inherently secure web application communication.
- B. SNMP is for network device management and is not used for securing web applications.
- C. FTP is for file transfer and is inherently insecure without additional encryption (like FTPS or SFTP).
TLS (Transport Layer Security)
A cryptographic protocol designed to provide communication security over a computer network. It is widely used for securing web browsing (HTTPS), email, instant messaging, and other data transfers.
- Successor to SSL (Secure Sockets Layer).
- Provides authentication, confidentiality, and integrity.
- Operates at the Transport Layer of the OSI model.
- Uses certificates for server authentication and key exchange.
Memory trick: HTTPS Uses TLS for Secure Data