Courseiva
Web App Injection Attacks →mediumMultiple Choice

GCIH Web App Injection Attacks Practice Question

What is the primary difference between Stored XSS and Reflected XSS?

⚠ Common exam trap

Students often focus incorrectly on the victim delivery mechanism rather than payload persistence, confusing how the attack reaches the user with where the malicious script actually resides in storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stored XSS permanently persists in the application, while Reflected XSS is transient.

The difference lies in the persistence of the payload. Stored XSS injects malicious code into the server's database or permanent storage, meaning every user viewing that page is automatically affected. Reflected XSS requires the victim to click a specially crafted link that includes the payload, which is then reflected back in the response. Understanding this distinction is vital for incident response, as Stored XSS implies a compromise of data integrity and wider impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stored XSS uses server-side scripts, whereas Reflected XSS uses client-side scripts.

    Why it's wrong here

    Both forms of XSS utilize client-side scripting (usually JavaScript) to execute within the victim's browser. The distinction is not in the type of script used, but in the storage location of the malicious payload. Stored XSS exists in the server database, while Reflected XSS exists only in the request.

  • ✗

    Reflected XSS is stored on the server, while Stored XSS is delivered via URLs.

    Why it's wrong here

    This statement is the exact opposite of the truth. Reflected XSS payloads are delivered in real-time through URLs or request parameters, while Stored XSS payloads are permanently saved in the application's persistent storage like a database, comment section, or profile page before being served to other users.

  • ✓

    Stored XSS permanently persists in the application, while Reflected XSS is transient.

    Why this is correct

    Stored XSS payloads reside in the application's back-end storage and are served to every user who accesses the affected page. Reflected XSS payloads are transient, meaning they are processed and immediately reflected back during a single request cycle, requiring a victim to initiate the specific trigger link.

  • ✗

    Reflected XSS is more dangerous because it bypasses CSRF tokens.

    Why it's wrong here

    The danger levels depend on the context, not CSRF tokens, which are separate security controls. Stored XSS is generally considered more dangerous because it can affect all users without individual interaction. CSRF is an entirely different class of vulnerability that focuses on forcing unwanted actions rather than script injection.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.