Study. uk . com
  1. Home
  2. All questions
  3. Question 587

CompTIA Security+ study material · question 587 of 611

Which two are identification and authentication failures? Choose two.

  1. Session identifiers that are never rotated
  2. An unencoded value rendered into an HTML page
  3. A publicly readable storage bucket
  4. Permitting unlimited brute-force attempts
Show the answer

Answer: A. Session identifiers that are never rotated
D. Permitting unlimited brute-force attempts

The other two are cross-site scripting and security misconfiguration respectively.

Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Identification and Authentication Failures

Challenge yourself on this topic → Study as cards