CompTIA CySA+ (CS0-003)Security OperationsMedium

During TLS traffic analysis in Wireshark, an analyst cannot decrypt the session but still needs to identify which domain a client is attempting to reach, even though the destination IP address resolves to a shared CDN used by thousands of unrelated sites. Which field within the unencrypted TLS handshake provides this information?

  1. ATLS session ticket
  2. BServer Name Indication (SNI)
  3. CIP time-to-live (TTL)
  4. DTCP window size
Show answer & explanation

Correct answer: B. Server Name Indication (SNI)

The Server Name Indication (SNI) field in the ClientHello message is sent in plaintext and specifies the hostname the client is trying to reach, allowing an analyst to identify the intended domain even on shared-IP CDN infrastructure. TCP window size and IP TTL relate to performance/fingerprinting, not domain identification, and session tickets are encrypted resumption data.

Why the other options are wrong

  • A. Session tickets are opaque, encrypted resumption tokens, not domain identifiers.
  • C. IP TTL helps with OS fingerprinting, not domain identification.
  • D. TCP window size affects flow control, unrelated to domain identification.

Server Name Indication (SNI)

A TLS extension included in the plaintext ClientHello that specifies the hostname the client wants to connect to, enabling servers hosting multiple domains on one IP to serve the correct certificate.

  • Visible in Wireshark even without decrypting the session
  • Useful for identifying C2 domains behind CDNs
  • Encrypted Client Hello (ECH) is an emerging mitigation that hides SNI

Memory trick: 'SNI is the shipping label still readable on a sealed box.'

More Security Operations questions