GCIH Web App Injection Attacks Practice Question
Exhibit
Content-Security-Policy: default-src 'self'; script-src 'self' https://trusted.cdn.com;
Refer to the exhibit. If an attacker successfully injects <script>alert(1)</script> into a page, what happens?
⚠ Common exam trap
Candidates often assume the script executes because they focus on the injection attempt itself rather than the active CSP policy that explicitly prevents such execution in the browser.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The browser blocks the script and logs a violation.
The CSP policy explicitly permits only scripts from the application's own origin ('self') and from the trusted CDN. Because the injected inline script does not match these sources, the browser will block its execution. This is a crucial security control because it forces the developer to rely on external files, rendering traditional inline XSS payloads useless. It effectively mitigates the risk by ensuring only scripts from trusted, verified locations can run.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The script executes successfully.
Why it's wrong here
The CSP header restricts script execution to 'self' and 'https://trusted.cdn.com'. Since the injected script is inline, it fails the policy constraints. Browsers will refuse to execute it and will typically report a CSP violation in the developer console, neutralizing the XSS attempt immediately upon page rendering.
- ✓
The browser blocks the script and logs a violation.
Why this is correct
The policy strictly restricts scripts to the origin and a specific CDN. Inline scripts are not allowed by the policy, so the browser identifies the violation, stops the script from running, and sends a report to the configured CSP reporting endpoint. This protects users from the malicious script execution.
- ✗
The browser executes the script only if the user is an admin.
Why it's wrong here
CSP is a security policy enforced by the browser for all users, regardless of their role or permission level. It does not contain logic for user roles. If the script violates the policy, the browser will block it for everyone, ensuring consistent security posture across the entire application user base.
- ✗
The browser automatically strips the script tags.
Why it's wrong here
The browser does not modify the HTML content to remove script tags. Instead, it enforces the policy by refusing to execute the code contained within those tags. The DOM may still contain the tags, but the security engine prevents the JavaScript engine from interpreting or running the injected code.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.