GSEC Web Communication Security Practice Question
A developer wants to prevent sensitive cookies from being transmitted over unencrypted HTTP connections. Which cookie attribute is specifically designed to enforce this requirement?
⚠ Common exam trap
Candidates mix up the Secure attribute with HttpOnly, mistakenly thinking HttpOnly enforces encryption during transit across the network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure
The Secure attribute is a critical security control for web applications. When a cookie is marked as Secure, the browser will only transmit that cookie if the request is being made over an encrypted connection, such as HTTPS. This prevents session tokens or sensitive data from being intercepted in cleartext via man-in-the-middle attacks, ensuring that transport-layer security is effectively utilized for all sensitive session-based interactions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HttpOnly
Why it's wrong here
The HttpOnly attribute prevents client-side scripts from accessing cookies via the Document.cookie API. While this is an essential defense against Cross-Site Scripting (XSS) attacks, it does not mandate encryption of the transport layer, which is the specific requirement for preventing cleartext interception over the network.
- ✗
SameSite=Strict
Why it's wrong here
The SameSite attribute is used to mitigate Cross-Site Request Forgery (CSRF) by controlling whether cookies are sent with cross-site requests. Setting it to Strict ensures the cookie is only sent in a first-party context, but this does not govern the encryption requirements of the underlying transport protocol.
- ✓
Secure
Why this is correct
The Secure flag instructs the browser to restrict the cookie transmission to encrypted (HTTPS) connections only. This is the primary mechanism for ensuring that sensitive session identifiers are not exposed in plaintext during network transit, providing a necessary layer of protection against sniffing and interception of data.
- ✗
Path=/secure
Why it's wrong here
The Path attribute restricts the scope of the cookie to a specific URL directory on the server. While this limits where the cookie is sent within an application, it provides no protection regarding the transport protocol and does not force the use of encrypted connections for transmission.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.