Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

An organization is subject to PCI DSS compliance and must ensure that all data transmitted between its cloud application and users is encrypted. Which encryption method should be enforced?

⚠ Common exam trap

CV0-004 often tests the confusion between an encryption algorithm (AES-256, SHA-256) and a transport protocol (TLS), so candidates pick the cipher name instead of the protocol that actually secures data in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TLS 1.2 or higher

PCI DSS requires that cardholder data transmitted over open, public networks be protected with strong cryptography. TLS 1.2 or higher is the transport-layer protocol that provides encryption, integrity, and authentication for data in transit between the cloud application and users, satisfying the requirement. AES-256 is the underlying cipher TLS uses, but it is not itself a transmission method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AES-256

    Why it's wrong here

    AES-256 is a symmetric cipher, not a transmission protocol; it specifies the algorithm but not how keys are exchanged or sessions established between users and the cloud application. It is tempting because PCI DSS mandates strong cryptography, and AES-256 would be correct as the cipher underlying TLS or at-rest encryption.

  • ✓

    TLS 1.2 or higher

    Why this is correct

    TLS 1.2 or higher encrypts data in transit between the cloud application and users, satisfying the PCI DSS requirement for protecting cardholder data over public networks. Earlier protocol versions contain known weaknesses, so enforcing TLS 1.2 as the minimum cipher suite baseline is mandatory.

  • ✗

    SHA-256

    Why it's wrong here

    SHA-256 is a hashing algorithm for integrity and signatures, not a cipher, so it cannot encrypt transmitted data at all. It is tempting because it appears in TLS cipher suites and certificate signatures, which would be correct for verifying integrity rather than providing confidentiality in transit.

  • ✗

    IPsec VPN

    Why it's wrong here

    IPsec VPN encrypts network traffic at the IP layer, typically for site-to-site or remote-access tunnels, not browser-to-cloud-application sessions. It is tempting because it does secure data in transit, and would be correct for connecting an on-premises network to Azure, but PCI DSS user-facing traffic requires TLS instead.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.