SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy
A development team is working on an application that requires secure communication between its front-end web server and a back-end API server. Both servers are within the same private network segment, but the data exchanged is highly sensitive. The team wants to ensure that the communication is both encrypted and authenticated. Which protocol combination would be most suitable for this purpose, assuming HTTP is the application layer protocol?
- AHTTP over TCP
- BHTTP over UDP
- CSSH (Secure Shell)
- DHTTPS (HTTP over TLS)
Show answer & explanationAnswer & explanation
Correct answer: D. HTTPS (HTTP over TLS)
HTTPS, which uses TLS (Transport Layer Security) to encrypt HTTP communication, provides both confidentiality (encryption) and integrity/authenticity (via digital certificates and cryptographic hashing) for data exchanged between the web server and API.
Why the other options are wrong
- A. HTTP over TCP provides no encryption or authentication beyond basic TCP, making it insecure for sensitive data.
- B. HTTP over UDP is not a standard or secure way to transmit sensitive data; UDP is connectionless and offers no inherent security.
- C. SSH is primarily for secure remote access and tunneling, not typically used directly for application-level data exchange between a web server and an API in this context, although it could tunnel other protocols.
HTTPS
Hypertext Transfer Protocol Secure (HTTPS) is an extension of the Hypertext Transfer Protocol (HTTP) for secure communication over a computer network. In HTTPS, the communication protocol is encrypted using Transport Layer Security (TLS), or its predecessor, Secure Sockets Layer (SSL).
- Provides confidentiality (encryption), integrity, and authenticity.
- Uses TLS/SSL to secure HTTP traffic.
- Requires server certificates to establish trust.
Memory trick: Secure connections need layers of trust and encryption.