Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 184 Topic 19 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 184 Topic 19 Discussion

312-50v13 Exam Topic 19 Question 184 Discussion:
Question #: 184
Topic #: 19

In Miami, Florida, cybersecurity analyst Laura Bennett is investigating unauthorized access incidents affecting Sunshine Credit Union’s online banking platform. Audit logs reveal that compromised accounts consistently involve users who accessed the portal through specially crafted links sent via email.

The links direct victims to the legitimate website, where they proceed to authenticate successfully. Shortly afterward, unauthorized access to the same accounts is observed without any additional credential guessing or brute-force activity.

Further examination shows that a value associated with the user’s interaction with the application remains unchanged throughout the authentication process and can be introduced before the user completes sign-in.

Which countermeasure should Laura implement to prevent this type of account takeover?


A.

Use restrictive cache directives such as Cache-Control: no-cache


B.

Implement SSL to encrypt all information in transit via the network


C.

Regenerate the session ID after a successful login


D.

Do not create sessions for unauthenticated users


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.