GSEC Web Communication Security Practice Question
A security analyst is examining a web application that uses HTTP Strict Transport Security (HSTS). The analyst notices that the HSTS header is only sent on HTTPS responses and includes the 'preload' directive. Which additional measure must be taken to ensure the domain is included in browser preload lists?
⚠ Common exam trap
The trap here is assuming that adding the 'preload' directive to the HSTS header is sufficient for browser preloading, when in fact manual submission and specific header requirements must be satisfied.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Submit the domain to the HSTS preload list maintained by Google, and ensure the header includes 'includeSubDomains' and a max-age of at least one year.
To preload HSTS, the domain must meet strict criteria: the HSTS header must include 'includeSubDomains', 'preload', and a max-age of at least one year. The 'preload' directive alone does not trigger automatic inclusion; the domain must be submitted to the preload list service. Once accepted, browsers hardcode the domain, enforcing HTTPS even on the first visit. This prevents SSL stripping attacks during initial connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Submit the domain to the HSTS preload list maintained by Google, and ensure the header includes 'includeSubDomains' and a max-age of at least one year.
Why this is correct
To be included in browser HSTS preload lists, the domain must be submitted to the preload list service (e.g., hstspreload.org) and meet specific requirements: the HSTS header must include 'includeSubDomains', 'preload', and a max-age of at least 31536000 seconds (one year). The preload directive signals intent, but submission is a separate manual step. This ensures the domain is hardcoded into browsers, providing protection even on the first visit.
- ✗
Ensure the HSTS header is sent with a max-age of at least six months and includes the 'preload' directive, then submit the domain to the preload list.
Why it's wrong here
The minimum max-age for preload eligibility is one year (31536000 seconds), not six months. While six months is a common starting point for HSTS, it does not meet the preload requirements. Additionally, the header must include 'includeSubDomains' to be eligible. Submitting with a shorter max-age or without 'includeSubDomains' will result in rejection. This option is a near-miss that highlights the specific thresholds required.
- ✗
Configure the server to redirect all HTTP requests to HTTPS with a 301 status code and include the HSTS header in the redirect response.
Why it's wrong here
Redirecting HTTP to HTTPS is a recommended practice, but HSTS headers are ignored by browsers when sent over HTTP; they are only processed over secure connections. Including the HSTS header in a redirect response over HTTP does not contribute to preload eligibility. The preload requirement focuses on the header sent over HTTPS and the submission process, not on redirect behavior. While redirects are good, they are not the specific additional measure needed for preloading.
- ✗
Add the 'preload' directive to the HSTS header and wait for browsers to automatically discover and add the domain to their preload lists.
Why it's wrong here
Browsers do not automatically discover and add domains to their preload lists; inclusion is a manual process that requires submission to a central list. The 'preload' directive alone does not trigger automatic inclusion. Without submission, the domain will never be preloaded, even if the header is correct. This option reflects a common misconception that the directive itself is sufficient, but it is only a declaration of intent.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.