Courseiva

GSEC Web Communication Security Practice Question

A developer wants to prevent sensitive cookies from being transmitted over unencrypted HTTP connections. Which cookie attribute is specifically designed to enforce this requirement?

⚠ Common exam trap

Candidates mix up the Secure attribute with HttpOnly, mistakenly thinking HttpOnly enforces encryption during transit across the network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secure

The Secure attribute is a critical security control for web applications. When a cookie is marked as Secure, the browser will only transmit that cookie if the request is being made over an encrypted connection, such as HTTPS. This prevents session tokens or sensitive data from being intercepted in cleartext via man-in-the-middle attacks, ensuring that transport-layer security is effectively utilized for all sensitive session-based interactions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HttpOnly

    Why it's wrong here

    The HttpOnly attribute prevents client-side scripts from accessing cookies via the Document.cookie API. While this is an essential defense against Cross-Site Scripting (XSS) attacks, it does not mandate encryption of the transport layer, which is the specific requirement for preventing cleartext interception over the network.

  • ✗

    SameSite=Strict

    Why it's wrong here

    The SameSite attribute is used to mitigate Cross-Site Request Forgery (CSRF) by controlling whether cookies are sent with cross-site requests. Setting it to Strict ensures the cookie is only sent in a first-party context, but this does not govern the encryption requirements of the underlying transport protocol.

  • ✓

    Secure

    Why this is correct

    The Secure flag instructs the browser to restrict the cookie transmission to encrypted (HTTPS) connections only. This is the primary mechanism for ensuring that sensitive session identifiers are not exposed in plaintext during network transit, providing a necessary layer of protection against sniffing and interception of data.

  • ✗

    Path=/secure

    Why it's wrong here

    The Path attribute restricts the scope of the cookie to a specific URL directory on the server. While this limits where the cookie is sent within an application, it provides no protection regarding the transport protocol and does not force the use of encrypted connections for transmission.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.