A web developer wants to protect their new web application from a man-in-the-middle attack. Which of the following controls would best prevent an attacker from stealing tokens stored in cookies?
A. Forcing the use of TLS for the web application​
B. Forcing the use of SSL for the web application​
C. Setting the secure attribute on the cookie​
D. Hashing the cookie value

Q&A Education