Cipher suite
The set of cryptographic algorithms a client and server agree to use for one TLS connection, covering key exchange, authentication, bulk encryption and integrity.
A cipher suite names the algorithms that protect a single Transport Layer Security (TLS) connection. In TLS 1.2 (RFC 5246) one identifier carries four choices: how the session keys are agreed, how the server proves its identity, which symmetric cipher encrypts the data, and which hash function supports integrity or key derivation. A name such as TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 reads left to right in that order: ephemeral elliptic curve Diffie-Hellman, an RSA certificate, AES-256 in GCM mode, and SHA-384.
The client lists the suites it supports in the TLS handshake, and the server picks one. If weak suites remain enabled on both sides, a connection can end up using one. Server hardening therefore means removing obsolete choices such as export-grade ciphers, RC4, and suites with no encryption, and preferring ephemeral key exchange, which gives forward secrecy. TLS 1.3 (RFC 8446) shortened the menu. Its suite names specify only the authenticated encryption cipher and the hash, key exchange and authentication are negotiated separately, and static RSA and static Diffie-Hellman key exchange are gone.
Exam relevance: a scenario is likely to describe a server that still accepts old ciphers and ask for the fix, which is configuration rather than a new certificate. Candidates are expected to read the parts of a TLS 1.2 suite name and to know that TLS 1.3 removed the static key exchanges.