- Home
- All questions
- Question 484
CISSP study material · question 484 of 500
A single sign-on integration leaves its tokens valid after the user logs out and after long periods of inactivity. How does OWASP classify this?
Show the answer
Answer: C. An authentication failure in its own right, separate from how the user originally proved identity.
OWASP's authentication failures entry includes not correctly invalidating user sessions or authentication tokens, mainly single sign-on tokens, during logout or a period of inactivity.
Source: OWASP Top 10 A07:2025 (OWASP) — OWASP Top 10:2025 A07 Authentication Failures > Description