Quiz 12 Question 14 of 20

A Suricata rule developer wants to write a rule that detects outbound HTTPS connections where the TLS SNI (Server Name Indication) contains a known malicious domain. Which Suricata keyword targets the TLS SNI field?

Select an answer to reveal the explanation.

Motivation