- Home
- All questions
- Question 235
CompTIA Security+ study material · question 235 of 611
Why must passwords and session tokens never be written to application logs?
Show the answer
Answer: D. Because logs are copied widely and retained long
Log data flows to many systems and survives for years, so a secret written there spreads far beyond its origin.
Source: OWASP Logging Cheat Sheet (OWASP) — OWASP Logging Cheat Sheet › Data to exclude