Explain the differences between TLS, SSL, and HTTPS, and what are the cyber security benefits?
When responding to this question, first define what each acronym stands for. TLS means Transport Layer Security. HTTPS is a hyper-text transfer protocol. In a network, HTTPS secures communications. Then discuss what they do. HTTPS is a secure HTTP version. An SSL/TLS connection secures any communication sent online. All ongoing communications between the browser and servers are encrypted safely. Finally, discuss the benefits they bring. Your cyber security depends on HTTPS, SSL, and TLS. Websites that don't include all the cyber security measures will get a penalty from Google.
"Securing and protecting our corporate website has always been our highest priority. When I assess how secure our sites are, I look at all the possible vulnerabilities within our systems and take the steps necessary to identify where those weaknesses might be. Let's say your site takes your viewers to a different page to use their credit cards and make purchases. If you did not use HTTPS to secure your site (that padlock image at the top left where the domain address is listed), or if it is incorrectly set up, the content can be intercepted by bad actors (hackers) on your site. I'm tuned into multiple IT news sources and software updates from all our software vendors on the latest hack attempts so that I'm always In the know. I've always had the practice of utilizing two SSL keys, one private key, and the other a public key that everyone knows."
"Say a client visits your site and sees that the information on your site can be easily intercepted; it does not leave an impression of credibility or trust. If your site is not reliable, secure, or safe, why would any client risk a purchase? If they can purchase something similar on a safer site, what would stop them? As a general rule, I always use the Handshake Protocol of TLS which enables authentications for clients and servers. I find this a more secure communication method after the first handshake is a success. If there is a failed handshake the first time, the connection terminates. I also use the STARTTLS (or STLS for POP3 protocol) command for outbound email connections for extra safety. A secure connection is required by specific ports to be able to connect. For example, I would use 995 for secure POP3, 443 for HTTPS, and 993 for IMAP. I already have these ports set up on our server."
Interviewers will ask several different questions about TLS, SSL, and HTTPS. Some of the common ones will be how each works and how they are used. You'll probably be asked to give examples of each in a hypothetical environment. We cover a few scenarios in the answer examples. It's important to do a thorough walk-through and give examples with scenarios of each.
Unlock all 47 Cyber Security questions
Prepare for technical scenarios and security assessments that interviewers prioritize.
Get Started