Akylade Certified Cyber Resilience Fundamentals ACCRF · Free Practice Question Medium
Question 19
An e-commerce company discovers that its payment gateway is susceptible to on-path attacks due to inadequate SSL/TLS protocols. What specific risk mitigation recommendation is most appropriate to address this issue?
- A Decrease the use of third-party payment services and other consultants to reduce complexity
- B Upgrade to the latest versions of SSL/TLS protocols and enforce strict certificate management practices
- C Focus on increasing physical security at company data centers
- D Implement a new marketing strategy and social media campaign to reassure customers about data security
Reveal correct answer
Correct answer: B
Explanation
Upgrading to the latest SSL/TLS protocols and enforcing strict certificate management directly addresses the vulnerability to man-in-the-middle attacks by ensuring secure, encrypted communications between clients and servers. Reducing the use of third-party services might simplify operations but does not resolve the fundamental issue with SSL/TLS protocols. While reassuring customers is beneficial, it does not address the technical vulnerability of the payment gateway. Increasing physical security, while important, does not mitigate the risk of man-in-the-middle attacks that occur during data transmission. For support or reporting issues, include Question ID: 662401950bf297753767cc7c in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
