Study. uk . com
  1. Home
  2. All questions
  3. Question 493

CISSP study material · question 493 of 500

A company maps support.example.com onto a support provider's infrastructure for convenience. Which consequence does OWASP's example describe?

  1. Every cookie set on the company's domain, including authentication cookies, is now sent to the provider, enabling session hijacking.
  2. The company's users are exposed to injection from the provider's application.
  3. The provider inherits the company's content security policy, weakening it.
  4. The provider's certificate becomes valid for the company's whole domain.
Show the answer

Answer: A. Every cookie set on the company's domain, including authentication cookies, is now sent to the provider, enabling session hijacking.

With such a mapping every cookie set on the company's domain, authentication cookies included, reaches the provider, letting anyone with access there hijack sessions.

Source: OWASP Top 10 A08:2025 (OWASP) — OWASP Top 10:2025 A08 Software or Data Integrity Failures > Example attack scenarios

Challenge yourself on this topic → Study as cards