- Home
- All questions
- Question 155
CompTIA Security+ study material · question 155 of 611
A team sets SameSite on its session cookie and removes its CSRF tokens. What is OWASP's position on this?
Show the answer
Answer: B. SameSite is defence in depth and does not replace tokens
SameSite reduces exposure but is treated as an additional layer rather than the primary control.
Source: OWASP Cross-Site Request Forgery Prevention Cheat Sheet (OWASP) — OWASP CSRF Prevention Cheat Sheet › SameSite Cookie Attribute