SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A company is developing a new mobile application that will handle sensitive customer financial data. Due to strict regulatory compliance requirements, the application must ensure end-to-end encryption for all data transmitted between the mobile device and the backend servers. Which protocol is most suitable for achieving this goal?
- AHTTPS
- BFTP
- CHTTP
- DSSH
Show answer & explanationAnswer & explanation
Correct answer: A. HTTPS
HTTPS (Hypertext Transfer Protocol Secure) encrypts HTTP communication using TLS/SSL, providing end-to-end encryption for web-based data transmission, which is standard for mobile applications communicating with backend servers.
Why the other options are wrong
- B. FTP is primarily for file transfer and typically lacks native encryption without additional layers like FTPS or SFTP.
- C. HTTP transmits data in plaintext, offering no encryption.
- D. SSH is used for secure remote access and tunneling, not typically for general application-level data transmission between a mobile app and a web service.
HTTPS
Hypertext Transfer Protocol Secure is an extension of HTTP for secure communication over a computer network. In HTTPS, the communication protocol is encrypted using Transport Layer Security (TLS), or its predecessor, Secure Sockets Layer (SSL).
- Provides authentication, data integrity, and confidentiality.
- Uses port 443 by default.
- Essential for protecting sensitive data in transit.
Memory trick: Secure protocols wrap your data in a safe, strong digital box.