N10-009 exam dumps

N10-009 practice question 245 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 245

Single answerLogical security: Encryption (Data in transit, Data at rest), Certificates (Public key infrastructure (PKI), Self-signed)

A company is deploying a new internal web application that stores employee tax documents on a file server. Employees will access the application from managed laptops over the corporate network and through a VPN when working remotely. The security team wants to ensure the documents are protected both while being transmitted and while stored, and they want users' browsers to trust the web application without certificate warnings. Which solution BEST meets these requirements?

  1. A

    Use HTTPS with a certificate issued by the company's internal PKI for the web server, and enable full-disk or file-level encryption on the server storing the tax documents.

  2. B

    Use HTTP for the application because the VPN already encrypts traffic, and use a self-signed certificate on the server for browser trust.

  3. C

    Use HTTPS with a self-signed certificate on the web server, and rely on NTFS permissions alone to protect the stored tax documents.

  4. D

    Use SSH port forwarding for employee browser access, and store the tax documents unencrypted because they are on an internal file server.

Show answer and explanation

Correct answer: A

Explanation

The key requirements are protection of data in transit, protection of data at rest, and trusted certificates for browsers. For data in transit, HTTPS using TLS is the standard control for web applications. For data at rest, technologies such as full-disk encryption or file-level encryption are appropriate because they protect stored data if the server or drives are lost, stolen, or accessed outside normal OS controls. For certificate trust, an internal PKI is the best fit for an internal application accessed by managed devices because the organization can distribute its root CA certificate through domain policy or endpoint management, allowing browsers to trust issued server certificates without warnings. Self-signed certificates can provide encryption but do not provide scalable trust and are generally unsuitable for production user-facing services unless manually trusted on every client. These practices align with common enterprise security guidance, including using TLS for web applications and using centrally managed certificate authorities for internal services.

  • A. Correct.

    Correct. HTTPS protects data in transit by using TLS to encrypt web sessions between the client and server. Using a certificate issued by the company's internal PKI allows managed devices to trust the certificate automatically if the internal root CA is deployed to those devices, avoiding browser warnings. Encrypting the stored tax documents with full-disk encryption or file-level encryption addresses data at rest, helping protect the files if the server or drives are stolen or improperly accessed offline.

  • B. Incorrect.

    Incorrect. A VPN can encrypt traffic between a remote device and the corporate network, but it does not eliminate the need to secure the application itself with HTTPS, especially since employees may also access it internally where application-layer encryption is still a best practice. In addition, a self-signed certificate does not inherently provide browser trust because clients do not trust it unless it is manually distributed and installed, which is not the same as using an internal PKI.

  • C. Incorrect.

    Incorrect. HTTPS would encrypt data in transit, but a self-signed certificate would typically cause browser warnings unless every client is configured to trust it. Also, NTFS permissions are access controls, not encryption. Permissions can restrict access for authorized users, but they do not protect the data at rest if the storage media is removed, stolen, or accessed outside the operating system's normal controls.

  • D. Incorrect.

    Incorrect. SSH port forwarding is not the standard or best solution for broad employee browser access to a web application in an enterprise environment. It adds complexity and does not address browser trust requirements in the same way as HTTPS with a trusted certificate. Leaving tax documents unencrypted at rest fails the requirement to protect stored sensitive data.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam