Study. uk . com
  1. Home
  2. All questions
  3. Question 366

CompTIA Security+ study material · question 366 of 611

Why should authorisation be checked on every request rather than cached for the session?

  1. Because checking is computationally cheap
  2. Because caching breaks federation assertions
  3. Because sessions cannot be revoked
  4. Because a revoked entitlement must take effect without waiting for the user to log out
Show the answer

Answer: D. Because a revoked entitlement must take effect without waiting for the user to log out

A cached decision keeps working after the underlying entitlement has been removed.

Source: NIST SP 800-207 (NIST) — SP 800-207 § 2.1 Tenets

Challenge yourself on this topic → Study as cards