Study. uk . com
  1. Home
  2. All questions
  3. Question 155

CompTIA Security+ study material · question 155 of 611

A team sets SameSite on its session cookie and removes its CSRF tokens. What is OWASP's position on this?

  1. SameSite must be combined with HttpOnly to prevent CSRF
  2. SameSite is defence in depth and does not replace tokens
  3. SameSite only applies to third-party analytics cookies
  4. It is correct, because SameSite fully prevents CSRF
Show the answer

Answer: B. SameSite is defence in depth and does not replace tokens

SameSite reduces exposure but is treated as an additional layer rather than the primary control.

Source: OWASP Cross-Site Request Forgery Prevention Cheat Sheet (OWASP) — OWASP CSRF Prevention Cheat Sheet › SameSite Cookie Attribute

Challenge yourself on this topic → Study as cards