DevNet Associate (DEVASC) v1.0Application Deployment and SecurityHard

A company is developing a highly sensitive financial application that will store customer account details. Due to strict regulatory compliance requirements, all data must be encrypted both when stored and when transmitted over the network. Which two cryptographic methods, when combined, would best meet these requirements?

  1. AMD5 for data at rest and HTTP for data in transit.
  2. BSHA-256 for data at rest and SSH for data in transit.
  3. CAES-256 for data at rest and TLS 1.3 for data in transit.
  4. DBase64 encoding for data at rest and UDP for data in transit.
Show answer & explanation

Correct answer: C. AES-256 for data at rest and TLS 1.3 for data in transit.

AES-256 is a strong symmetric encryption algorithm widely used for data at rest encryption, meeting regulatory standards. TLS 1.3 (Transport Layer Security) is the latest and most secure protocol for encrypting data in transit over a network, providing confidentiality and integrity for transmitted data. Combining these two provides robust protection for both states.

Why the other options are wrong

  • A. MD5 is a hashing algorithm (not encryption) and is cryptographically broken; HTTP provides no encryption for data in transit.
  • B. SHA-256 is a hashing algorithm (not encryption); while SSH provides secure tunnels, TLS is generally preferred for web application data in transit.
  • D. Base64 is an encoding scheme, not encryption; UDP is a connectionless protocol and provides no inherent encryption for data in transit.

Comprehensive Data Encryption

Comprehensive data encryption involves applying strong cryptographic methods to protect data across all its states: at rest (stored) and in transit (over networks).

  • Data at Rest: AES-256 is a strong standard.
  • Data in Transit: TLS 1.3 (or 1.2) is the current standard.
  • Ensures confidentiality and integrity.
  • Critical for regulatory compliance (e.g., PCI DSS, GDPR).

Memory trick: AES rests, TLS travels; together they're strong.

More Application Deployment and Security questions