- Home
- All questions
- Question 285
CompTIA Security+ study material · question 285 of 611
At which moment must an application regenerate the session identifier to prevent session fixation?
Show the answer
Answer: A. Immediately after a successful login
Regeneration at any privilege change, above all at login, invalidates an identifier the attacker planted beforehand.
Source: OWASP Session Management Cheat Sheet (OWASP) — OWASP Session Management Cheat Sheet › Renew the Session ID After Any Privilege Level Change