Free CompTIA PenTest+ PT0-002 Practice Question

A penetration tester is conducting an assessment against a web application and has observed that session tokens are not rotated after login. Which type of attack could the penetration tester employ to take advantage of this vulnerability?

  • Session replay

  • Cross-site scripting (XSS)

  • Session fixation

  • Cross-site request forgery (CSRF)

This question's topic:
CompTIA PenTest+ PT0-002 / 
Attacks and Exploits
Your Score:

Check or uncheck an objective to set which questions you will receive.