ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A security team is deploying a new web application that will handle sensitive customer data. They need to ensure that all communication between the client's browser and the web server is encrypted and that the server's identity is verified. Which protocol combination should be implemented?
- AHTTPS with TLS
- BTelnet with SSH
- CHTTP with FTP
- DSMTP with POP3
Show answer & explanationAnswer & explanation
Correct answer: A. HTTPS with TLS
HTTPS (Hypertext Transfer Protocol Secure) combines HTTP with TLS (Transport Layer Security) to provide encrypted communication and server identity verification for web traffic. This ensures data confidentiality and integrity, and authenticates the server to the client.
Why the other options are wrong
- B. Telnet is unencrypted for remote terminal access, and SSH is a secure alternative for remote access, neither is for web application traffic.
- C. HTTP is unencrypted, and FTP is for file transfer, not secure web browsing.
- D. SMTP and POP3 are email protocols, not for securing web application communication.
HTTPS and TLS
HTTPS is the secure version of HTTP, using TLS (Transport Layer Security) to encrypt communication and verify the identity of the web server.
- HTTPS ensures confidentiality and integrity of web data.
- TLS provides encryption and authentication.
- Essential for protecting sensitive data exchanged over the web.
Memory trick: HTTPS is HTTP wearing its TLS 'security suit'.