PEN-200 • Practice Test 12
Free PEN-200 practice test — 15 questions with explanations. Set 12. No signup required.
You are testing an e-commerce application that uses a cookie named 'sessionid' to maintain authenticated sessions. The application sets this cookie without the HttpOnly attribute, and you have identified a reflected XSS vulnerability in the product search feature. Which of the following attack methods would allow you to steal the session cookie and hijack an authenticated user's session?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.