A company’s security policy states that all Web browsers must automatically delete their HTTP browser cookies
upon terminating. What sort of security breach is this policy attempting to mitigate?
A.
Attempts by attackers to access Web sites that trust the Web browser user by stealing the user’s
authentication credentials.
B.
Attempts by attackers to access the user and password information stored in the company’s SQL database.
C.
Attempts by attackers to access passwords stored on the user’s computer without the user’s knowledge.
D.
Attempts by attackers to determine the user’s Web browser usage patterns, including when sites were
visited and for how long.
Explanation:
Cookies can store passwords and form content a user has previously entered, such as a credit card number or
an address.
Cookies can be stolen using a technique called cross-site scripting. This occurs when an attacker takes
advantage of a website that allows its users to post unfiltered HTML and JavaScript content.
https://en.wikipedia.org/wiki/HTTP_cookie#Cross-site_scripting_.E2.80.93_cookie_theft