hardMultiple Choice
CAS-004 Practice Question: During a security assessment, a penetration…
During a security assessment, a penetration tester discovers that a web application's session tokens are predictable. The application uses a custom session management system. Which of the following is the MOST effective remediation to ensure secure session tokens?
⚠ Common exam trap
CompTIA often tests the misconception that regenerating tokens frequently or using HMAC with a secret key is sufficient, when in fact the core issue is insufficient entropy in the token generation process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Generate session tokens using a cryptographically secure random number generator (CSPRNG) with at least 128 bits of entropy.
Predictable session tokens arise from insufficient randomness. Using a cryptographically secure random number generator (CSPRNG) with at least 128 bits of entropy ensures that tokens are statistically unpredictable and resistant to brute-force or guessing attacks, which is the foundational requirement for secure session management per NIST SP 800-63B and OWASP guidelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Generate session tokens using a cryptographically secure random number generator (CSPRNG) with at least 128 bits of entropy.
Why this is correct
A CSPRNG seeded with sufficient entropy removes the predictability that let attackers forecast tokens. The 128-bit minimum makes brute-force guessing infeasible, directly addressing the custom session system's weakness by replacing deterministic generation with cryptographically strong randomness.
- ✗
Regenerate the session token on each page request.
Why it's wrong here
Regenerating tokens per request breaks session continuity and still leaves the generation algorithm predictable, so an attacker can forecast the next value. It is tempting because rotation limits token reuse, which is correct for preventing fixation, not for fixing weak entropy in a custom generator.
- ✗
Implement a short session timeout of 5 minutes.
Why it's wrong here
A five-minute timeout shrinks the window for exploiting a guessed token but does not make the token itself unpredictable, so an attacker can still hijack sessions within that window. It is tempting because short timeouts limit exposure, which is correct for reducing risk from stolen tokens, not for remediating weak generation.
- ✗
Generate tokens using HMAC-SHA256 of a timestamp and a secret key.
Why it's wrong here
HMAC-SHA256 of a timestamp with a secret key still yields predictable tokens when timestamps are guessable and the key is static; it provides integrity, not unpredictability. It is tempting because HMAC is a sound construction, but it is correct only when combined with a cryptographically random nonce.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.