Courseiva
Networking and Protocols →mediumMultiple Choice

GSEC Networking and Protocols Practice Question

A security analyst is reviewing a packet capture of traffic between a user workstation and a public web server. The analyst observes the workstation completing a three-way handshake on TCP port 443, then negotiating encryption parameters, and finally requesting a specific resource path. The analyst wants to confirm that the client verified the identity of the server before any application data was sent. Which protocol mechanism in this exchange provides that server identity verification?

⚠ Common exam trap

The trap here is assuming the TCP three-way handshake or an application header authenticates the server, when only the TLS certificate validation does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The TLS handshake, where the server presents a certificate and the client validates it against trusted certificate authorities.

Server identity in HTTPS is established during the TLS handshake, where the server proves possession of a private key matching a certificate that the client validates against trusted roots and the requested hostname. The TCP handshake merely creates the connection, and application headers such as Host are client-supplied and unauthenticated. Confirming the certificate chain is what binds the session to a verified server identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server's TCP initial sequence number, which is randomized to prevent session hijacking.

    Why it's wrong here

    Randomized initial sequence numbers make off-path TCP injection harder by preventing an attacker from guessing the next expected sequence value. That is a transport-layer integrity measure, not an identity check. It says nothing about who operates the server, does not involve certificates or keys, and would not satisfy the analyst's goal of confirming the server's authenticated identity before data transfer.

  • ✗

    The HTTP Host header, which tells the server which virtual host the client intends to reach.

    Why it's wrong here

    The Host header is an application-layer field used for virtual host routing; it is supplied by the client and is trivially spoofable. It does not authenticate the server and, in TLS, is normally encrypted inside the tunnel. An attacker could present any certificate while the Host header still names the legitimate site, so this header cannot verify server identity in the scenario described.

  • ✗

    The TCP SYN, SYN-ACK, ACK sequence confirms the server's identity before data transfer.

    Why it's wrong here

    The three-way handshake only establishes a reliable transport connection and synchronizes sequence numbers; it carries no cryptographic proof of the server's identity. Any host that answers on port 443 would complete the handshake. In this scenario the analyst needs proof tied to a certificate and key, which the handshake cannot supply, so relying on the SYN/SYN-ACK/ACK exchange would misidentify the security control actually protecting the session.

  • ✓

    The TLS handshake, where the server presents a certificate and the client validates it against trusted certificate authorities.

    Why this is correct

    During the TLS handshake the server transmits its X.509 certificate, and the client verifies the signature chain up to a trusted root, checks the subject name against the requested host, and confirms validity dates. Only after this validation does the client derive session keys and send the HTTP request. This is precisely the mechanism that authenticates the server's identity before application data flows on port 443.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.