CV0-004 Security Practice Question
An organization is subject to PCI DSS compliance and must ensure that all data transmitted between its cloud application and users is encrypted. Which encryption method should be enforced?
⚠ Common exam trap
CV0-004 often tests the confusion between an encryption algorithm (AES-256, SHA-256) and a transport protocol (TLS), so candidates pick the cipher name instead of the protocol that actually secures data in transit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TLS 1.2 or higher
PCI DSS requires that cardholder data transmitted over open, public networks be protected with strong cryptography. TLS 1.2 or higher is the transport-layer protocol that provides encryption, integrity, and authentication for data in transit between the cloud application and users, satisfying the requirement. AES-256 is the underlying cipher TLS uses, but it is not itself a transmission method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AES-256
Why it's wrong here
AES-256 is a symmetric cipher, not a transmission protocol; it specifies the algorithm but not how keys are exchanged or sessions established between users and the cloud application. It is tempting because PCI DSS mandates strong cryptography, and AES-256 would be correct as the cipher underlying TLS or at-rest encryption.
- ✓
TLS 1.2 or higher
Why this is correct
TLS 1.2 or higher encrypts data in transit between the cloud application and users, satisfying the PCI DSS requirement for protecting cardholder data over public networks. Earlier protocol versions contain known weaknesses, so enforcing TLS 1.2 as the minimum cipher suite baseline is mandatory.
- ✗
SHA-256
Why it's wrong here
SHA-256 is a hashing algorithm for integrity and signatures, not a cipher, so it cannot encrypt transmitted data at all. It is tempting because it appears in TLS cipher suites and certificate signatures, which would be correct for verifying integrity rather than providing confidentiality in transit.
- ✗
IPsec VPN
Why it's wrong here
IPsec VPN encrypts network traffic at the IP layer, typically for site-to-site or remote-access tunnels, not browser-to-cloud-application sessions. It is tempting because it does secure data in transit, and would be correct for connecting an on-premises network to Azure, but PCI DSS user-facing traffic requires TLS instead.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.