Courseiva
Web Communication Security →mediumMultiple Choice

GSEC Web Communication Security Practice Question

A security analyst is reviewing a web application that allows users to upload profile pictures. The application accepts files with .jpg and .png extensions, but the analyst discovers that an attacker can upload a file named 'avatar.php.jpg' and then access it directly via a URL. The server executes the file as PHP. Which security control would most directly prevent this type of attack?

⚠ Common exam trap

The trap here is assuming that client-side controls like CSP or transport encryption can mitigate server-side file execution vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store uploaded files outside the web root and serve them via a handler that validates file content.

The vulnerability arises because the server executes uploaded files based on their extension or content. Storing files outside the web root and serving them through a validating handler prevents direct execution and ensures only safe content is delivered. This approach directly addresses the root cause, whereas other controls like CSP, HTTPS, or cookie flags do not stop server-side code execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store uploaded files outside the web root and serve them via a handler that validates file content.

    Why this is correct

    Storing files outside the web root prevents direct URL access, and a validating handler ensures only safe file types are served. This combination stops the server from executing the uploaded file, because the file is never placed in a location where the web server would interpret it as code. It directly mitigates the vulnerability by removing the execution path and enforcing content validation.

  • ✗

    Implement a strict Content Security Policy (CSP) that disallows inline scripts.

    Why it's wrong here

    A Content Security Policy restricts which scripts can execute in the browser, but it does not prevent the server from executing an uploaded file. In this scenario, the attacker uploads a file that the server interprets as PHP, leading to server-side code execution. CSP operates on the client side and would not stop the server from processing the malicious file, so it fails to address the root cause.

  • ✗

    Enforce HTTPS for all upload and download requests to prevent man-in-the-middle attacks.

    Why it's wrong here

    HTTPS encrypts data in transit and protects against interception, but it does not affect how the server handles uploaded files. The attack described involves the server executing a malicious file after it has been uploaded, which can occur even over HTTPS. Therefore, enforcing HTTPS does not prevent this server-side code execution vulnerability.

  • ✗

    Set the 'secure' attribute on session cookies to ensure they are only sent over encrypted connections.

    Why it's wrong here

    The 'secure' attribute ensures cookies are transmitted only over HTTPS, protecting session tokens from interception. However, it has no bearing on file upload handling or server-side execution of uploaded files. This control addresses session security, not the vulnerability of executing user-supplied files, so it would not prevent the attack.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.