ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium
A financial institution is migrating its legacy systems to a modern cloud-native architecture. They need to ensure that data in transit between microservices, and between the application and external clients, is protected from eavesdropping and tampering. Which cryptographic method is most suitable for establishing secure communication channels in this scenario?
- ATransport Layer Security (TLS)
- BHashing with SHA-256
- CAsymmetric encryption with RSA
- DSymmetric encryption with AES-256
Show answer & explanationAnswer & explanation
Correct answer: A. Transport Layer Security (TLS)
Transport Layer Security (TLS) is a cryptographic protocol designed to provide secure communication over a computer network. It uses a combination of asymmetric encryption for key exchange, symmetric encryption for data confidentiality, and hashing for integrity, making it ideal for protecting data in transit between clients and servers, and between microservices.
Why the other options are wrong
- B. Hashing provides integrity but not confidentiality or protection against tampering in transit.
- C. Asymmetric encryption is too slow for bulk data encryption and is primarily used for key exchange and digital signatures.
- D. Symmetric encryption provides confidentiality but key exchange is problematic without an underlying secure channel.
Transport Layer Security (TLS)
A cryptographic protocol that provides end-to-end security of data sent between applications over the internet.
- Secures web traffic (HTTPS), email, VPNs, and other network communication.
- Uses asymmetric cryptography for handshake and key exchange, and symmetric cryptography for bulk data encryption.
- Provides confidentiality, integrity, and authentication for communication.
Memory trick: TLS is the secure tunnel for your data's journey.