If an administrator configures session management for an application server to use SSL ID tracking, which two other session tracking mechanisms should also be enabled?
Cookies
URL Rewriting
Security Integration
Serial Access
RMI