ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A company policy mandates that all data exchanged between its internal network and its cloud-hosted applications must be encrypted in transit and authenticated. The company uses Amazon Web Services (AWS) for its cloud infrastructure. Which security measure is most appropriate for securing this communication?
- AVirtual Private Cloud (VPC)
- BSecurity Groups
- CTLS/SSL Encryption
- DDirect Connect
Show answer & explanationAnswer & explanation
Correct answer: C. TLS/SSL Encryption
TLS/SSL encryption is the primary protocol used to secure data in transit over networks, including between on-premises and cloud environments. It provides both encryption and authentication, fulfilling the policy requirement for securing data exchange.
Why the other options are wrong
- A. A Virtual Private Cloud (VPC) provides an isolated network in the cloud but does not, by itself, encrypt data in transit to/from on-premises.
- B. Security Groups act as virtual firewalls within AWS, controlling access to instances, but don't encrypt data in transit between networks.
- D. AWS Direct Connect provides a dedicated network connection but doesn't inherently encrypt application-level traffic.
TLS/SSL (Transport Layer Security/Secure Sockets Layer)
Cryptographic protocols that provide secure communication over a computer network, primarily used for encrypting and authenticating data in transit between a client and a server.
- Encrypts data to ensure confidentiality.
- Provides authentication to verify identities.
- Protects data integrity during transmission.
- Widely used for web (HTTPS), email, and VPNs.
Memory trick: TLS/SSL is like a 'secure envelope' for all your data, ensuring it's private and authentic on its journey.