Q1: Which key exchange property is a baseline design goal in TLS 1.3
Multiple ChoiceAn attacker records certificate-authenticated TLS 1.3 connections that use fresh ECDHE shares, then later obtains the server's long-term certificate private key. The review asks which property limits retrospective decryption.