- Home
- All questions
- Question 463
CompTIA Security+ study material · question 463 of 611
How does session hijacking differ from credential theft?
Show the answer
Answer: B. It bypasses authentication entirely by using an already-authenticated session
The attacker never authenticates, which is why multi-factor authentication alone does not stop it.
Source: OWASP Session Management Cheat Sheet (OWASP) — OWASP Session Management Cheat Sheet › Session Attacks