- Home
- All questions
- Question 289
CompTIA Security+ study material · question 289 of 611
Why should a session identifier never be carried in the URL?
Show the answer
Answer: A. It leaks through browser history, proxy logs and the Referer header
A cookie is not written into any of those places, which is why the identifier belongs there instead.
Source: OWASP Session Management Cheat Sheet (OWASP) — OWASP Session Management Cheat Sheet › Session ID Exchange Mechanisms