mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is exploiting a web…
A penetration tester is exploiting a web application that stores session tokens in HTTP cookies without the HttpOnly flag. Which attack is most likely to succeed?
⚠ Common exam trap
Many candidates confuse session hijacking via XSS with CSRF, but CSRF does not steal the token—it only abuses the existing authenticated session to perform actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session hijacking through cross-site scripting
The absence of the HttpOnly flag on session cookies allows client-side scripts (e.g., JavaScript) to access the cookie. An attacker can exploit a cross-site scripting (XSS) vulnerability to execute arbitrary JavaScript in the victim's browser, which then reads the session cookie and sends it to the attacker. This enables session hijacking without needing to guess or brute-force the token.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection
Why it's wrong here
Structured Query Language (SQL) injection attacks target the backend database by manipulating input to alter queries, potentially exfiltrating credentials, PII, or other stored data. However, a session token in a cookie is typically held in the client's browser memory and is not directly readable through SQLi unless the application stores tokens in a database and you can query them, which is an uncommon chained attack. In a direct web application exploit, SQLi does not execute client-side script or read cookie values, making it an incorrect explanation for session token theft.
- ✓
Session hijacking through cross-site scripting
Why this is correct
Session hijacking through cross-site scripting (XSS) is the correct explanation because reflected, stored, or DOM-based XSS allows an attacker to inject arbitrary JavaScript that executes in the victim's browser context. If the session cookie lacks the HttpOnly flag, the injected script can access document.cookie and send the session token to an attacker-controlled server, enabling session hijacking. This is a direct client-side attack that compromises the confidentiality of the session token.
- ✗
Cross-site request forgery
Why it's wrong here
Cross-site request forgery (CSRF) is a confidentiality-neutral attack that forces an authenticated victim to send crafted, state-changing requests to a trusted site, such as transferring funds or changing email. It does not steal or exfiltrate the session token; rather, it abuses the browser's automatic inclusion of cookies (including the session cookie) to make the forged request appear legitimate. Because the attacker never learns the token value, CSRF is not a session-token theft technique.
- ✗
Server-side request forgery
Why it's wrong here
Server-side request forgery (SSRF) occurs when an attacker tricks the vulnerable server into making arbitrary HTTP requests to either internal or external resources, potentially accessing sensitive internal systems or cloud metadata. It operates at the server layer and does not interact with the victim's browser or its session cookies, so it cannot read or exfiltrate a session token. SSRF's impact lies in pivoting within the network or accessing internal services, not in hijacking a client's session.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.