SY0-701 exam dumps

SY0-701 practice question 137 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 137

Single answerEncryption

A security administrator is deploying encryption for a web-based payroll application that is accessed by employees over the internet. The organization wants to ensure the confidentiality of payroll data in transit while minimizing the risk of using outdated or weak cryptographic protocols. Which of the following is the BEST solution to implement?

  1. A

    Configure the application to use TLS 1.3 with certificates issued by a trusted CA

  2. B

    Use WPA3 to encrypt employee sessions between their browsers and the payroll server

  3. C

    Enable AES-256 on the database server only, because encrypting stored data also protects web traffic

  4. D

    Configure SSL 3.0 with a strong certificate, because the certificate strength compensates for the protocol version

Show answer and explanation

Correct answer: A

Explanation

The key requirement in this scenario is protecting payroll data in transit for a public-facing web application. The appropriate control is HTTPS using a modern version of TLS, with TLS 1.3 being the best answer because it is the current recommended protocol version for secure web transport. It provides confidentiality, integrity, and authenticated server identity when used with valid digital certificates. By contrast, WPA3 protects wireless links, not internet web sessions; database encryption protects data at rest, not in transit; and SSL 3.0 is deprecated due to security vulnerabilities. Best practices from NIST and common industry guidance recommend disabling deprecated protocols such as SSL and older TLS versions where possible, and using modern TLS configurations with trusted certificates for web services.

  • A. Correct.

    TLS 1.3 with certificates from a trusted certificate authority is the best choice for protecting web traffic in transit. TLS is the standard protocol used to secure HTTPS sessions between browsers and web servers. TLS 1.3 removes support for many older, insecure cryptographic options and improves security compared to earlier SSL and TLS versions. Using trusted CA-issued certificates also helps clients validate the server's identity and reduces the likelihood of certificate warnings or man-in-the-middle attacks.

  • B. Incorrect.

    WPA3 is used to secure wireless network communications between a client device and a wireless access point, not browser-to-server application sessions across the internet. A candidate might pick this option because WPA3 is a strong encryption standard, but it operates at the wireless network layer and does not replace HTTPS/TLS for web applications.

  • C. Incorrect.

    Encrypting the database server can help protect data at rest, but it does not secure the transmission of payroll information between employee browsers and the web application. This option reflects a common misconception that encrypting stored data automatically protects data in transit. Separate controls are needed for data at rest and data in transit.

  • D. Incorrect.

    SSL 3.0 is obsolete and insecure. Even if a strong certificate is used, the protocol itself has known weaknesses and should not be deployed. Certificate strength does not compensate for a deprecated transport security protocol. This distractor targets the misconception that certificates alone provide security regardless of the protocol version in use.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam