All three mechanisms - cookies, hidden form fields, and SSL sessions - are valid methods for session tracking in web applications. Cookies are the most common, hidden fields provide a fallback, and SSL sessions leverage the secure session identifier. Different applications may use one or multiple of these approaches.