About this interactive
When you connect to a site you have never visited, you want three things: that it really is the site you meant, that nobody in the middle can read what goes back and forth, and that nobody can change it on the way. TLS gives you authenticity, confidentiality and integrity, and it does it with two main protocols inside the TLS protocol.
The TLS record protocol does the bulk of the work. It fragments the data into records and reassembles them at the other end, it encrypts and decrypts them, and it verifies their integrity. Sum it up as confidentiality and integrity.
The TLS handshake protocol runs first. It exchanges the keys, negotiates the cryptographic parameters (which TLS version, which cipher suite) and does the authentication, proving the server is who it says it is. Sum it up as authentication, plus establishing the parameters the record protocol then uses for confidentiality and integrity.
One thing to keep straight: the server's certificate and its public key belong to the handshake. They prove who the server is and protect the key exchange. The traffic itself is encrypted by the record protocol with symmetric session keys.
To sort each card, ask: is this protecting the data as it moves (record), or setting up and proving the connection before the data moves (handshake)?
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →