Which statement best describes an insecure protocol/service/port?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

Which statement best describes an insecure protocol/service/port?

Explanation:
An insecure protocol/service/port is one that does not provide enough protection for data in transit, specifically lacking safeguards for confidentiality and/or data integrity. If data can be read by someone else or altered while it’s being transmitted, those protections aren’t in place. Lacking these controls is the core issue, which is why describing it as not having confidentiality and/or integrity protections best captures the risk. The other statements describe scenarios that are either secure (always using encryption and strong authentication by default, or only supporting secure channels) or focus on a symptom like clear-text transmission. While clear-text transmission is a common insecure trait, the essential idea is the absence of proper confidentiality and integrity protections.

An insecure protocol/service/port is one that does not provide enough protection for data in transit, specifically lacking safeguards for confidentiality and/or data integrity. If data can be read by someone else or altered while it’s being transmitted, those protections aren’t in place. Lacking these controls is the core issue, which is why describing it as not having confidentiality and/or integrity protections best captures the risk.

The other statements describe scenarios that are either secure (always using encryption and strong authentication by default, or only supporting secure channels) or focus on a symptom like clear-text transmission. While clear-text transmission is a common insecure trait, the essential idea is the absence of proper confidentiality and integrity protections.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy