CompTIA PenTest+ PT0-002 Practice Question
A penetration tester is conducting an assessment against a web application and has observed that session tokens are not rotated after login. Which type of attack could the penetration tester employ to take advantage of this vulnerability?
Session replay
Session fixation
Cross-site scripting (XSS)
Cross-site request forgery (CSRF)