Data in transit
Data moving between systems, sites or users across a network, also called data in motion, and exposed to interception and tampering along the way unless the channel is protected.
Data in transit, also called data in motion, is information travelling across a network: between a browser and a web server, between data centres, or from a device to a cloud service. It is one of the three data states. The main threats are interception through packet sniffing, alteration or redirection through a man-in-the-middle attack, and replay of captured traffic.
Protection comes mainly from encrypted, authenticated channels. TLS protects application traffic such as web, email and API calls, IPsec protects traffic at the network layer, commonly as a VPN, and SSH protects administrative sessions and file transfers. These protocols combine confidentiality with integrity checks and peer authentication, so they help against tampering as well as eavesdropping. A useful distinction is between link encryption, where traffic is decrypted and re-encrypted at each hop, and end-to-end encryption, where only the endpoints hold the keys. Encryption in transit stops protecting the data once it arrives: at the far end it becomes data at rest or data in use and needs the controls for that state.
Exam relevance: a scenario is likely to describe data crossing an untrusted network and ask for the matching control. Candidates are expected to choose an encrypted channel such as TLS, IPsec or SSH, and not to count storage encryption as protection for traffic on the wire.