Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A network administrator needs to ensure that…

A network administrator needs to ensure that sensitive financial data remains confidential while in transit over the internet. Which technology should they implement?

⚠ Common exam trap

The trap is conflating encryption algorithms (AES) or integrity primitives (SHA-256, digital signatures) with the transport protocol (TLS) that actually secures data in transit — candidates often pick AES-256 because it sounds like 'strong encryption' without realizing it lacks the transport framing and key exchange.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TLS 1.3

TLS 1.3 is the correct choice because it is a transport-layer cryptographic protocol specifically designed to provide confidentiality (encryption) and integrity for data in transit over untrusted networks like the internet. It negotiates ephemeral session keys via a handshake and encrypts application traffic using AEAD ciphers such as AES-GCM or ChaCha20-Poly1305. The other options address different security goals or operate at different layers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Digital signatures

    Why it's wrong here

    Digital signatures provide authenticity, integrity and non-repudiation, not confidentiality — they leave the payload readable in transit. They are tempting because they do protect data against tampering and impersonation, and would be the right choice when the requirement is proving a message's origin rather than concealing its contents.

  • ✗

    SHA-256

    Why it's wrong here

    SHA-256 is a hashing algorithm providing integrity, not confidentiality; it cannot encrypt data in transit. It is tempting because it appears in TLS cipher suites and certificate signatures, so it would be correct when verifying that transmitted data has not been altered.

  • ✓

    TLS 1.3

    Why this is correct

    TLS 1.3 encrypts data in transit between client and server, providing confidentiality over untrusted internet paths. It satisfies the in-transit confidentiality requirement, and its removal of legacy ciphers and RSA key exchange strengthens forward secrecy compared with earlier TLS versions.

  • ✗

    AES-256

    Why it's wrong here

    AES-256 is a symmetric cipher operating on data at rest or inside a tunnel; alone it encrypts no internet traffic, so confidentiality in transit is unmet. It is tempting because AES-256 is genuinely the encryption algorithm used by TLS and IPsec, and would be correct for encrypting a stored file or volume.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.