Parks procurement reviews a playground-vendor site whose homepage brand does not match the organization named on the public TLS certificate. How should that mismatch be used?
Select an answer to reveal the explanation.
Short Explanation
A TLS certificate is like the name on the deed while the homepage is the painted sign. When they disagree, that is a due-diligence flag, not a license to attack TLS. Write down the public cert fields and keep collecting.
Full Explanation
Public certificate details, including certificate-transparency and browser-visible subject fields, are website-OSINT clues. An organization name on the certificate that disagrees with homepage branding is a vendor due-diligence flag, not proof that exploitation is authorized. Branding does not override PKI observations, and requesting private keys is not collection. Record the public fields with the rest of the site artifacts.