Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 24 Topic 3 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 24 Topic 3 Discussion

312-50v13 Exam Topic 3 Question 24 Discussion:
Question #: 24
Topic #: 3

During a red team assessment at Sunshine Credit Union in Miami, ethical hacker Laura demonstrates a weakness in the company ' s session handling process. She shows that once a user logs in, the same authentication token assigned before login continues to be valid without being refreshed. Laura explains that an attacker could exploit this flaw by tricking a victim into authenticating with a value already known to the attacker, gaining access afterward. To mitigate this risk, the IT team agrees to apply a countermeasure focused on proper session lifecycle management.

Which countermeasure should the IT team implement?


A.

Implement SSL to encrypt all information in transit via the network


B.

Use restrictive cache directives for all the web traffic through HTTP and HTTPS


C.

Regenerate the session ID after a successful login to prevent session fixation attacks


D.

Do not create sessions for unauthenticated users unless necessary


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.