ISC2 Certified in Cybersecurity (CC)Network SecurityMedium

A company policy mandates that all data exchanged between its internal network and its cloud-hosted applications must be encrypted in transit and authenticated. The company uses Amazon Web Services (AWS) for its cloud infrastructure. Which security measure is most appropriate for securing this communication?

  1. AVirtual Private Cloud (VPC)
  2. BSecurity Groups
  3. CTLS/SSL Encryption
  4. DDirect Connect
Show answer & explanation

Correct answer: C. TLS/SSL Encryption

TLS/SSL encryption is the primary protocol used to secure data in transit over networks, including between on-premises and cloud environments. It provides both encryption and authentication, fulfilling the policy requirement for securing data exchange.

Why the other options are wrong

  • A. A Virtual Private Cloud (VPC) provides an isolated network in the cloud but does not, by itself, encrypt data in transit to/from on-premises.
  • B. Security Groups act as virtual firewalls within AWS, controlling access to instances, but don't encrypt data in transit between networks.
  • D. AWS Direct Connect provides a dedicated network connection but doesn't inherently encrypt application-level traffic.

TLS/SSL (Transport Layer Security/Secure Sockets Layer)

Cryptographic protocols that provide secure communication over a computer network, primarily used for encrypting and authenticating data in transit between a client and a server.

  • Encrypts data to ensure confidentiality.
  • Provides authentication to verify identities.
  • Protects data integrity during transmission.
  • Widely used for web (HTTPS), email, and VPNs.

Memory trick: TLS/SSL is like a 'secure envelope' for all your data, ensuring it's private and authentic on its journey.

More Network Security questions