An analyst uses tshark to extract certificate fields from an Enterprise municipal capture. What analysis purpose does that serve?
Select an answer to reveal the explanation.
Short Explanation
Pulling cert fields from an Enterprise capture is about trust clues—what the client was told to believe—not a PSK shortcut or a RoE waiver.
Full Explanation
In Enterprise EAP-TLS oriented captures, analysts may inspect certificate metadata to understand trust anchors and how clients validate servers—concepts that inform evil-twin and mis-validation themes. That analysis does not derive a Personal PSK length, enable WPS, or substitute for authorization. It remains a traffic-analysis purpose within scope.