New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CSSLP Exam - Topic 2 Question 35 Discussion

Actual exam question for ISC2's CSSLP exam
Question #: 35
Topic #: 2
[All CSSLP Questions]

You work as a Network Administrator for uCertify Inc. You need to secure web services of your company in order to have secure transactions. Which of the following will you recommend for providing security?

Show Suggested Answer Hide Answer
Suggested Answer: A

The Secure Sockets Layer (SSL) is a commonly-used protocol for managing the security of a message transmission on the Internet. SSL has

recently been succeeded by Transport Layer Security (TLS), which is based on SSL. SSL uses a program layer located between the Internet's

Hypertext Transfer Protocol (HTTP) and Transport Control Protocol (TCP) layers. SSL is included as part of both the Microsoft and Netscape

browsers and most Web server products. URLs that require an SSL connection start with https: instead of http:.

Answer C is incorrect. S/MIME (Secure/Multipurpose Internet Mail Extensions) is a standard for public key encryption and signing of e-

mail encapsulated in MIME. S/MIME provides the following cryptographic security services for electronic messaging applications: authentication,

message integrity, non-repudiation of origin (using digital signatures), privacy, and data security (using encryption).

Answer D is incorrect. Hypertext Transfer Protocol (HTTP) is a client/server TCP/IP protocol used on the World Wide Web (WWW) to

display Hypertext Markup Language (HTML) pages. HTTP defines how messages are formatted and transmitted, and what actions Web

servers and browsers should take in response to various commands. For example, when a client application or browser sends a request to

the server using HTTP commands, the server responds with a message containing the protocol version, success or failure code, server

information, and body content, depending on the request. HTTP uses TCP port 80 as the default port.

Answer B is incorrect. A Virtual Private Network (VPN) is a computer network that is implemented in an additional software layer

(overlay) on top of an existing larger network for the purpose of creating a private scope of computer communications or providing a secure

extension of a private network into an insecure network such as the Internet.

The links between nodes of a Virtual Private Network are formed over logical connections or virtual circuits between hosts of the larger

network. The Link Layer protocols of the virtual network are said to be tunneled through the underlying transport network.


Contribute your Thoughts:

0/2000 characters
Leonida
4 months ago
Wait, are people still using HTTP for anything? That's wild!
upvoted 0 times
...
Esteban
4 months ago
HTTP? Seriously? That's not secure at all!
upvoted 0 times
...
Naomi
4 months ago
S/MIME is great for email, but not really for web services, right?
upvoted 0 times
...
Elise
4 months ago
I think VPN is more for secure connections, not just web services.
upvoted 0 times
...
Raul
5 months ago
Definitely SSL, it's a must for secure transactions!
upvoted 0 times
...
Agustin
5 months ago
S/MIME sounds familiar for email security, but I can't recall if it applies to web services. This is tricky!
upvoted 0 times
...
Selma
5 months ago
I practiced a similar question where SSL was the clear choice for securing web services. I hope that's still the case!
upvoted 0 times
...
Pansy
5 months ago
I think VPNs are more for secure remote access, not specifically for web services. I might lean towards SSL.
upvoted 0 times
...
Shakira
5 months ago
I remember studying SSL for securing web transactions, but I'm not entirely sure if it's the best option here.
upvoted 0 times
...
Ashton
5 months ago
Ugh, I'm not totally sure about the TOGAF ADM version numbers. Let me think this through carefully and see if I can eliminate some of the options.
upvoted 0 times
...
Rodolfo
5 months ago
This looks like a tricky question. I'll need to think carefully about the difference between @Stateless and @Stateful beans and how passivation works.
upvoted 0 times
...
Laurel
5 months ago
This seems like a straightforward question about medical errors. I'm pretty confident I can identify the correct type of error described in the scenario.
upvoted 0 times
...

Save Cancel