Study. uk . com
  1. Home
  2. All questions
  3. Question 29

CISSP study material · question 29 of 500

A federal agency hardens a public web service and its internal client tooling against NIST SP 800-52 Rev. 2. Both endpoints currently negotiate TLS 1.2 and offer FIPS-approved cipher suites only. The architect asks what further protocol support the guidance obliges the agency to provide.

  1. Servers had to support TLS 1.3 by 1 January 2024, while clients could remain on TLS 1.2 only.
  2. Clients had to support TLS 1.3 by 1 January 2024, while servers could remain on TLS 1.2 only.
  3. Servers and clients alike had to support TLS 1.3 as well, with 1 January 2024 set as the deadline.
  4. Servers and clients alike had to stop negotiating TLS 1.2 once TLS 1.3 support was in place.
Show the answer

Answer: C. Servers and clients alike had to support TLS 1.3 as well, with 1 January 2024 set as the deadline.

The guidance requires TLS 1.2 with approved suites and set 1 January 2024 for TLS 1.3 support on servers and clients alike; TLS 1.2 is retained, not dropped.

Source: NIST SP 800-52 Rev. 2 (NIST) — SP 800-52 Rev. 2 > Abstract

Challenge yourself on this topic → Study as cards