Courseiva
hardMultiple Choice

200-201 Is developing a new cloud-based application Practice Question

An organization is developing a new cloud-based application. The security policy requires that all data be encrypted in transit and at rest. Which combination of controls meets this requirement?

⚠ Common exam trap

200-201 often tests the misconception that a single control (VPN, HTTPS, or TDE) satisfies both in-transit and at-rest requirements — candidates must recognize that two distinct controls are needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use HTTPS and encrypt the database with TDE

The requirement is encryption both in transit and at rest. HTTPS (TLS) encrypts data in transit between clients and the application, while Transparent Data Encryption (TDE) encrypts the database files at rest. Using both together satisfies the dual requirement, making option D the only complete answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a VPN for all connections

    Why it's wrong here

    VPN encrypts data in transit but not at rest.

  • ✗

    Encrypt the database using Transparent Data Encryption (TDE)

    Why it's wrong here

    TDE encrypts database files at rest but does nothing for data moving across the network. TDE is the right control when the requirement is limited to protecting stored database contents, not the in-transit half of this policy.

  • ✗

    Use HTTPS for all communication

    Why it's wrong here

    HTTPS encrypts data in transit only; it provides no encryption for data stored at rest in databases, buckets or volumes. HTTPS is the correct control when the requirement covers only transport security, not the at-rest half of this policy.

  • ✓

    Use HTTPS and encrypt the database with TDE

    Why this is correct

    HTTPS enforces TLS between client and server, covering data in transit. Transparent Data Encryption encrypts database files and backups at rest without application changes. Together they satisfy both halves of the policy's encryption mandate across the application's communication and storage layers.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.