ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium
A company is deploying a new cloud-based application that requires secure communication between its on-premises data center and the cloud provider's Virtual Private Cloud (VPC). The solution must ensure data confidentiality and integrity during transit and allow for dynamic routing updates between networks. Which secure communication channel technology is best suited for this requirement?
- ATransport Layer Security (TLS)
- BHTTPS
- CIPsec VPN
- DSecure Shell (SSH)
Show answer & explanationAnswer & explanation
Correct answer: C. IPsec VPN
IPsec VPNs provide secure, encrypted tunnels between networks, ensuring confidentiality and integrity for all traffic passing through. They support dynamic routing protocols (e.g., BGP) for robust connectivity between data centers and cloud VPCs, which is crucial for dynamic routing updates.
Why the other options are wrong
- A. TLS secures application-layer communication (e.g., web traffic) between two endpoints, not typically for full network-to-network secure tunnels with routing.
- B. HTTPS is HTTP over TLS, securing web traffic, which is too specific for general secure network-to-network communication with dynamic routing.
- D. SSH is primarily for secure remote command-line access or file transfer, not for establishing a site-to-site secure network tunnel with dynamic routing.
IPsec VPN
A suite of protocols that provides cryptographic security for IP communications, often used to create secure tunnels (VPNs) between networks.
- Operates at the network layer (Layer 3).
- Provides confidentiality, integrity, and authentication.
- Supports both tunnel and transport modes.
Memory trick: IPsec builds tunnels, TLS secures streams.