Exam 312-50v13 Topic 1 Question 479 Discussion
Actual exam question for ECCouncil's 312-50v13 exam
Question #: 479
Topic #: 1
Question #: 479
Topic #: 1
A penetration tester is assessing a mobile application and discovers that the app is vulnerable to improper session management. The session tokens are not invalidated upon logout, allowing the tokens to be reused. What is the most effective way to exploit this vulnerability?
Suggested Answer: C Vote an answer
When session tokens are not invalidated on logout, an attacker can reuse a previously captured token to regain authenticated access, which is a classic session replay attack exploiting improper session termination.
by Jonas at Sep 18, 2026, 09:49 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).