Session management
Protecting an authenticated session through its life: a random session secret issued at sign-in, carried only over protected channels, and ended on timeout, logout or expiry.
After authentication, a session lets a user keep working without authenticating again for each request. NIST SP 800-63B-4 section 5 bases it on a session secret, such as a browser cookie, that the service generates in response to the authentication event. The ISC2 exam outline lists session management in 5.2. Whoever presents a bearer session secret is treated as the session’s owner, so session management is largely about protecting that secret: generating it from an approved random source, sending it only over protected channels such as TLS, and issuing a fresh one at each sign-in.
A session ends on an inactivity timeout, an overall time limit or logout, and can be extended by reauthentication. On logout the secret should be invalidated at the service as well as erased in the browser, since closing a window may leave a valid secret behind. SP 800-63B-4 also says a session is not to be treated as stronger than the authentication that created it. Weak session handling can lead to session hijacking.
Exam relevance: a scenario involving a stolen cookie, a logout that leaves the session usable, or a missing timeout is likely to turn on session management. Candidates are expected to treat the session secret as a bearer credential, not as a second factor.