ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium
A security architect is reviewing the design of a new e-commerce platform. The platform requires secure communication between the web server and the database server, both residing within the same secure data center segment. While network segmentation is in place, the architect wants to ensure that specific application traffic between these two servers is encrypted and authenticated, without requiring full VPN tunnels or complex network-wide IPsec configurations. Which secure communication channel technology is most appropriate for this specific application-layer requirement?
- AMulti-Protocol Label Switching (MPLS)
- BTransport Layer Security (TLS)
- CSecure Shell (SSH)
- DVirtual Private Network (VPN)
Show answer & explanationAnswer & explanation
Correct answer: B. Transport Layer Security (TLS)
TLS is designed to provide secure communication over a computer network, commonly used for encrypting application-layer traffic. It's ideal for securing specific server-to-server communication within a data center without the overhead of full network-layer VPNs.
Why the other options are wrong
- A. MPLS is a data-carrying mechanism for high-performance telecommunications networks, primarily for routing efficiency, not for end-to-end encryption or authentication of application data.
- C. SSH is primarily used for secure remote access to command-line interfaces and tunneling, not typically for general application-to-application data encryption at scale.
- D. VPNs (often IPsec-based) operate at the network layer and are typically used for site-to-site or remote access, which is overkill for specific application-layer security between servers in the same segment.
Transport Layer Security (TLS)
A cryptographic protocol designed to provide communication security over a computer network, widely used for encrypting web traffic and other application-layer data.
- Operates at the transport layer of the OSI model.
- Provides confidentiality, integrity, and authentication.
- Successor to SSL (Secure Sockets Layer).
Memory trick: TLS 'Secures' the 'Talk' between 'Apps'.