What is the purpose of session management in PHP web applications?
A). To maintain stateful information across multiple requests
B). To optimize database queries
C). To handle user authentication
D). To manage server configurations
Which of the following is a security best practice for session management?
A). Use HTTPS to encrypt session data during transmission
B). Store session data in plaintext on the server
C). Set session cookies to expire after every request
D). Share session IDs in URL parameters
What is the role of hashing in user authentication?
A). To securely store passwords
B). To encrypt session data
C). To generate random session IDs
D). To validate IP addresses
What is the purpose of using prepared statements in user authentication?
A). To prevent SQL injection attacks
B). To optimize database queries
C). To increase server performance
D). To store session data securely
What is the recommended approach for handling session data in PHP forms?
A). Use form validation and CSRF tokens
B). Store session data in hidden form fields
C). Use plaintext passwords for form authentication
D). Share session data in URL parameters
How can you securely manage session data in PHP?
A). Store sensitive session data server-side
B). Store session data in plaintext on the client
C). Share session data in URL parameters
D). Store session data in unencrypted cookies
Which PHP function is commonly used to hash passwords?
A). password_hash()
B). hash_password()
C). encrypt_password()
D). secure_hash()
What is the primary benefit of salting passwords before hashing?
A). To prevent rainbow table attacks
B). To increase server performance
C). To encrypt session data
D). To generate random session IDs
How can you prevent session fixation attacks in PHP?
A). Regenerate session IDs after successful authentication
B). Use weak session IDs
C). Store session IDs in plaintext
D). Disable session management entirely
Which of the following is commonly used for user authentication in PHP?
A). Username and password
B). Session ID
C). IP address
D). URL parameters