GSEC Malicious Code and Exploit Mitigation Practice Question
A penetration tester is assessing a web application and finds that user input is reflected into an HTML page without encoding. The tester wants to demonstrate that an attacker could steal a victim's session cookie by injecting a script that sends the cookie to an external server. Which mitigation, when implemented by the developers, most directly prevents this specific cookie theft even if the input reflection remains?
⚠ Common exam trap
The trap here is choosing the root-cause fix (output encoding) when the question explicitly asks for the control that protects the cookie even if the reflection remains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the session cookie with the HttpOnly attribute.
The HttpOnly attribute makes the session cookie inaccessible to client-side scripts, so a reflected script injection cannot read or exfiltrate it. This directly counters the described attack even though the reflection vulnerability remains. While output encoding would fix the root cause and a strict Content Security Policy would reduce script execution, the question asks for the most direct prevention of cookie theft given the reflection, and HttpOnly is that control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the session cookie with the HttpOnly attribute.
Why this is correct
The HttpOnly attribute prevents client-side scripts from accessing the cookie through document.cookie, so even a successful reflected script injection cannot read and exfiltrate the session cookie. This directly neutralizes the described theft technique while leaving the reflection bug in place. It is a targeted, server-side cookie attribute that requires no changes to input handling and is the most direct mitigation for script-based session cookie theft.
- ✗
Add the Secure attribute to the session cookie.
Why it's wrong here
The Secure attribute ensures the cookie is only transmitted over HTTPS, which protects it from network eavesdropping but does nothing to stop a script running in the page from reading document.cookie. Since the attack is client-side script injection, the cookie is already accessible to the script regardless of transport security. Secure is an important defense-in-depth measure but does not address the specific theft technique described.
- ✗
Enable Content Security Policy with a strict script-src directive.
Why it's wrong here
A strict Content Security Policy can block inline script execution and thereby stop many reflected script injections, which is a strong defense. However, the scenario specifically asks for the mitigation that most directly prevents cookie theft even if the input reflection remains, and CSP operates at the page level and can be bypassed by misconfigurations or allowed script sources. HttpOnly is a narrower, more deterministic control for protecting the cookie itself, so CSP is not the most direct answer here.
- ✗
Implement output encoding for all user-supplied data.
Why it's wrong here
Output encoding is the correct root-cause fix for reflected script injection and would prevent the script from executing at all. But the scenario stipulates that the reflection remains, and asks for the mitigation that most directly prevents cookie theft despite that reflection. Output encoding addresses the injection point, not the cookie's exposure, so it does not meet the specific condition described in the question.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.