U.S. Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 3 Question 9 Discussion

In the OSI model for network communication, the Session Layer is responsible for:
A) establishing a connection and terminating it when it is no longer needed.
B) presenting data to the receiver in a form that it recognizes.
C) adding appropriate network addresses to packets.
D) transmitting the data on the medium.

IIBA-CCA Exam - Topic 3 Question 9 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 9
Topic #: 3
[All IIBA-CCA Questions]

In the OSI model for network communication, the Session Layer is responsible for:

Show Suggested Answer Hide Answer
Suggested Answer: A

The OSI Session Layer (Layer 5) is responsible for establishing, managing, and terminating sessions between communicating applications. A session is the logical dialogue that allows two endpoints to coordinate how communication starts, how it continues, and how it ends. This includes controlling the ''conversation'' state, such as who can transmit at what time, maintaining the session so it stays active, and closing it cleanly when it is no longer needed. Because of this, option A best matches the Session Layer's core responsibilities.

In contrast, presenting data to the receiver in a recognizable form is the job of the Presentation Layer (Layer 6), which deals with formatting, encoding, compression, and often cryptographic transformation concepts. Adding appropriate network addresses to packets aligns to the Network Layer (Layer 3), where logical addressing and routing decisions occur, typically associated with IP addressing. Transmitting the data on the medium is handled at the Physical Layer (Layer 1), which concerns signals, cabling, and the actual movement of bits.

From a cybersecurity perspective, session management is important because weaknesses can enable session hijacking, replay, or fixation, especially when session identifiers are predictable, not protected, or not properly invalidated. Controls commonly include strong authentication, secure session token generation, timeout and reauthentication rules, and proper session termination to reduce exposure.


Contribute your Thoughts:

0/2000 characters
Queen
1 month ago
I practiced a question like this before, and I think A was the right answer then too. It’s about establishing and terminating connections, right?
upvoted 0 times
...
Lezlie
2 months ago
I remember something about the Session Layer, but I keep mixing it up with the Presentation Layer. Wasn’t that one about data formats?
upvoted 0 times
...
Fairy
2 months ago
I think the Session Layer is about managing connections, so I’m leaning towards A, but I’m not entirely sure.
upvoted 0 times
...

Save Cancel