Study. uk . com
  1. Home
  2. All questions
  3. Question 235

CompTIA Security+ study material · question 235 of 611

Why must passwords and session tokens never be written to application logs?

  1. Because logs cannot be encrypted
  2. Because it would breach the retention schedule
  3. Because log parsers reject long strings
  4. Because logs are copied widely and retained long
Show the answer

Answer: D. Because logs are copied widely and retained long

Log data flows to many systems and survives for years, so a secret written there spreads far beyond its origin.

Source: OWASP Logging Cheat Sheet (OWASP) — OWASP Logging Cheat Sheet › Data to exclude

Challenge yourself on this topic → Study as cards