- Home
- All questions
- Question 287
CompTIA Security+ study material · question 287 of 611
Which property must a session identifier have?
Show the answer
Answer: D. It should be long and generated by a cryptographically secure random generator
A counter or a derived value can be predicted, which lets an attacker guess a valid session without stealing one.
Source: OWASP Session Management Cheat Sheet (OWASP) — OWASP Session Management Cheat Sheet › Session ID Properties