Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium

A network security engineer is configuring a web server to ensure that all communication between clients and the server is encrypted and authenticated. The engineer specifically wants to prevent man-in-the-middle attacks and ensure the integrity of the data exchanged. Which protocol combination is most appropriate for achieving these goals for web traffic?

  1. AHTTP and FTP
  2. BHTTPS and TLS
  3. CSSH and Telnet
  4. DSMTP and POP3
Show answer & explanation

Correct answer: B. HTTPS and TLS

HTTPS (Hypertext Transfer Protocol Secure) is HTTP combined with SSL/TLS (Transport Layer Security). TLS provides encryption for confidentiality, digital certificates for authentication (preventing MITM), and cryptographic hashing for data integrity, making it the ideal solution for securing web traffic.

Why the other options are wrong

  • A. HTTP and FTP transmit data in cleartext and offer no encryption or authentication against MITM.
  • C. SSH provides secure remote access, and Telnet is insecure; neither is primarily for general web traffic.
  • D. SMTP and POP3 are email protocols; while they can be secured with TLS, they are not primarily for general web traffic.

HTTPS (Hypertext Transfer Protocol Secure)

HTTPS is the secure version of HTTP, using SSL/TLS to encrypt communication, authenticate the server, and ensure data integrity between a web browser and a website.

  • Uses TLS for encryption
  • Authenticates the web server to the client
  • Protects against eavesdropping and tampering

Memory trick: HTTPS is HTTP with a secure 'S' for TLS.

More Network Security questions