People say "SSL" but almost always mean TLS. SSL is the deprecated predecessor; TLS is the protocol that actually secures HTTPS today. The exam expects you to know SSL is dead and why.
Last updated July 2026
| Aspect | SSL | TLS |
|---|---|---|
| Full name | Secure Sockets Layer | Transport Layer Security |
| Status | Deprecated and insecure | Current standard |
| Versions | SSL 2.0 and 3.0 (both broken) | TLS 1.0 and 1.1 (retired), 1.2, and 1.3 (current) |
| Known attacks | POODLE and DROWN exploit SSL directly | TLS 1.2 and 1.3 close those holes |
| Handshake | Slower, more round trips | TLS 1.3 needs one round trip and drops weak ciphers |
| Forward secrecy | Not guaranteed | Standard in TLS 1.3 (ephemeral key exchange) |
| Use it today? | No, disable SSL entirely | Yes, TLS 1.2 or 1.3 |
SSL and TLS do the same job, encrypting data in transit, but every SSL version is broken and should be disabled. "SSL certificate" is just a marketing holdover; the protocol doing the work is TLS. On the exam, if a server still allows SSL 3.0 the fix is to turn it off and require TLS 1.2 or higher.
Reading the difference is a start. SecPlus Mastery drills it with over 1,000 practice questions, timed mock exams, and spaced review across all five SY0-701 domains, so it sticks for exam day.
Written to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.