- Home
- All questions
- Question 29
CISSP study material · question 29 of 500
A federal agency hardens a public web service and its internal client tooling against NIST SP 800-52 Rev. 2. Both endpoints currently negotiate TLS 1.2 and offer FIPS-approved cipher suites only. The architect asks what further protocol support the guidance obliges the agency to provide.
Show the answer
Answer: C. Servers and clients alike had to support TLS 1.3 as well, with 1 January 2024 set as the deadline.
The guidance requires TLS 1.2 with approved suites and set 1 January 2024 for TLS 1.3 support on servers and clients alike; TLS 1.2 is retained, not dropped.
Source: NIST SP 800-52 Rev. 2 (NIST) — SP 800-52 Rev. 2 > Abstract