How can you prevent session fixation attacks in PHP?
A). Regenerate session IDs after successful authentication
B). Use weak session IDs
C). Store session IDs in plaintext
D). Disable session management entirely
How can you implement remember me functionality in PHP?
A). By using persistent cookies with long expiration times
B). By storing passwords in plaintext
C). By disabling session management
D). By using URL parameters for authentication
What is the recommended approach for handling session data in PHP forms?
A). Use form validation and CSRF tokens
B). Store session data in hidden form fields
C). Use plaintext passwords for form authentication
D). Share session data in URL parameters
What does the $_SESSION superglobal array store in PHP?
A). Session data
B). User credentials
C). Database queries
D). HTML markup
Which of the following is a security best practice for session management?
A). Use HTTPS to encrypt session data during transmission
B). Store session data in plaintext on the server
C). Set session cookies to expire after every request
D). Share session IDs in URL parameters
What is the purpose of user authentication in PHP web applications?
A). To verify the identity of users accessing the application
B). To optimize database queries
C). To manage user sessions
D). To handle server configurations
Which of the following is commonly used for user authentication in PHP?
A). Username and password
B). Session ID
C). IP address
D). URL parameters
What is the primary benefit of salting passwords before hashing?
A). To prevent rainbow table attacks
B). To increase server performance
C). To encrypt session data
D). To generate random session IDs
What does the session_regenerate_id() function do in PHP?
A). Regenerates the session ID to prevent session fixation
B). Registers a new session ID with the server
C). Retrieves the session ID from the server
D). Ends the current session and deletes session data
What is the purpose of the session_write_close() function in PHP?
A). Writes session data and closes the session file
B). Opens a new session file for writing
C). Ends the current session and deletes session data
D). Retrieves the session data from the session file