CCT 372: Stolen Sessions and Why MFA Never Saw Them (CISSP Domain 5.6)
カートのアイテムが多すぎます
カートに追加できませんでした。
ウィッシュリストに追加できませんでした。
ほしい物リストの削除に失敗しました。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
Send us Fan Mail
A stolen password is annoying. A stolen session token can be invisible, valid, and instantly profitable. Today we dig into a real warning sign from Okta threat intelligence: infostealer malware lifted live session tokens from browsers, and thousands of Google sessions were still working weeks later. No MFA prompt. No brute force. Just a legitimate session replayed by the wrong person, with real dollar damage through unauthorized usage and credits.
We use that story to sharpen the CISSP Domain 5.6 mindset around implementing authentication systems and, more importantly, validating tokens after sign-in. I walk through why authentication and token validation are different security functions with different “owners,” why forcing password resets does not invalidate an attacker’s existing session, and what a token signature does and does not prove. Then we get practical: audience claim checks, expiration and token lifetime ceilings, scope validation, and why “skipping the audience check breaks nothing in testing” is exactly how breaches scale.
We also cover the controls that shrink risk when you cannot reliably detect theft: short access token lifetimes, narrow scoping to limit blast radius, hardware-backed signing key storage, and automated key rotation with defined crypto periods. To lock it in, we run through four CISSP-style questions and explain the traps so you can answer like a risk-focused manager, not a spec reciter.
Subscribe for more CISSP exam training, share this with a teammate who owns IAM, and leave a review so more candidates can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!