Correct Answer: Enforcing current TLS versions with strong cipher suites for web and API traffic, using IPsec with Perfect Forward Secrecy for site-to-site tunnels, and regularly auditing supported protocol versions and cipher configurations
Explanation: Enforcing current TLS versions with strong ciphers, IPsec with Perfect Forward Secrecy, and regular audits together provide strong modern protection, unlike indefinitely supporting the oldest TLS versions, using static never-rotated IPsec keys, disabling certificate validation, deliberately using the weakest cipher suite, or never auditing protocol/cipher configuration.
Correct Answer: Enforcing current TLS versions with strong cipher suites for web and API traffic, using IPsec with Perfect Forward Secrecy for site-to-site tunnels, and regularly auditing supported protocol versions and cipher configurations
Explanation: Enforcing current TLS versions with strong ciphers, IPsec with Perfect Forward Secrecy, and regular audits together provide strong modern protection, unlike indefinitely supporting the oldest TLS versions, using static never-rotated IPsec keys, disabling certificate validation, deliberately using the weakest cipher suite, or never auditing protocol/cipher configuration.