
Session Management and Insecure Deserialization
Authored by official garbage
Computers
University
Used 2+ times

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
41 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
20 sec • 1 pt
What are the potential problems with the approach of creating a session ID by concatenating user_id and time?
Session ID is too long
Does not utilize hashing
Can be predicted by an attacker
Uses time function too frequently
2.
MULTIPLE CHOICE QUESTION
20 sec • 1 pt
What is the main vulnerability of storing session tokens in cookies as shown?
Session fixation
XSS
Lack of HttpOnly and Secure
SQL Injection
3.
MULTIPLE CHOICE QUESTION
20 sec • 1 pt
What is the main risk if session timeout is set too long (e.g., 24 hours)?
Application crash
Too frequent logouts
Increased potential for session hijacking
Issues with database indexing
4.
MULTIPLE CHOICE QUESTION
20 sec • 1 pt
What is the main protection against session hijacking when users are on public networks?
Using a special port
Adding captcha
Enabling Secure and HttpOnly on cookies
Storing session in URL
5.
MULTIPLE CHOICE QUESTION
20 sec • 1 pt
Why is storing session tokens in localStorage considered risky?
Tokens can be lost after refresh
Cannot be read by the server
Vulnerable to XSS
Not compatible with all browsers
6.
MULTIPLE CHOICE QUESTION
20 sec • 1 pt
What type of attack is the code 'document.cookie = "sessionid=123abc";' vulnerable to?
CSRF
Clickjacking
XSS
Deserialization
7.
MULTIPLE CHOICE QUESTION
20 sec • 1 pt
What is the best practice when a user logs out of an application?
Remove token from client only
Remove session from server and client
Delete cookie with script
Disable session timeout
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Microsoft
or continue with
%20(1).png)
Apple
Others
Already have an account?