Study. uk . com
  1. Home
  2. All questions
  3. Question 463

CompTIA Security+ study material · question 463 of 611

How does session hijacking differ from credential theft?

  1. It requires the victim to be offline
  2. It bypasses authentication entirely by using an already-authenticated session
  3. It only works against unencrypted connections
  4. It requires administrative privileges
Show the answer

Answer: B. It bypasses authentication entirely by using an already-authenticated session

The attacker never authenticates, which is why multi-factor authentication alone does not stop it.

Source: OWASP Session Management Cheat Sheet (OWASP) — OWASP Session Management Cheat Sheet › Session Attacks

Challenge yourself on this topic → Study as cards