Building-inspection leadership wants analysts to accept every cookie banner on target vendor sites while signed into the city's main domain account. What should the analyst do instead?
Select an answer to reveal the explanation.
Short Explanation
Accepting every cookie while wearing the city's SSO badge is like touring a warehouse in a labeled city jacket and then filling out their guestbook. The vendor learns who is looking, and the tracking profile gets messy. Research identity and cookie consent belong in an isolated profile, not the main civic login.
Full Explanation
Using an identifiable civic single sign-on account on target vendor sites can reveal the investigating agency and pollute tracking graphs with official identity. PORP OPSEC isolates research browsing so cookie consent, sessions, and attribution stay in a controlled lab profile. Proving a visit via vendor analytics, substituting another official mailbox, or collecting from production workstations increases exposure rather than reducing it.