GSEC Web Communication Security Practice Question
A security engineer is configuring a web server to enforce secure communication and prevent man-in-the-middle attacks. The engineer wants to implement HTTP Strict Transport Security (HSTS) and ensure that it is properly deployed. Which TWO of the following are required for HSTS to be effective? (Choose two.)
⚠ Common exam trap
The trap here is assuming that HTTP-to-HTTPS redirects are required for HSTS, when in fact HSTS bypasses HTTP entirely after the initial header is received.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The HSTS header must be served over a valid HTTPS connection with a trusted certificate.
HSTS is enabled when the server sends the Strict-Transport-Security header over a trusted HTTPS connection. The browser then enforces HTTPS for future requests. A valid certificate is necessary for the browser to accept the header. Redirects and includeSubDomains are optional enhancements, and specific TLS versions are not mandated by HSTS itself. Therefore, the required elements are the header over HTTPS and a trusted certificate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The HSTS header must include the includeSubDomains directive to protect all subdomains.
Why it's wrong here
The includeSubDomains directive extends HSTS protection to subdomains, but it is optional. HSTS can be effective for the primary domain without it. The question asks for required conditions for HSTS to be effective, not for maximum coverage. Therefore, includeSubDomains is not a strict requirement for basic HSTS functionality.
- ✓
The HSTS header must be served over a valid HTTPS connection with a trusted certificate.
Why this is correct
For the browser to accept and enforce HSTS, the header must be received over HTTPS with a certificate that the browser trusts. If the certificate is invalid or self-signed, the browser will not process the HSTS header, and the policy will not be applied. Therefore, a valid HTTPS connection is necessary for HSTS to be effective.
- ✓
The server must include the Strict-Transport-Security header in HTTPS responses.
Why this is correct
HSTS is activated by the server sending the Strict-Transport-Security header over HTTPS. The browser will then enforce HTTPS for future requests to that domain. Without this header, the browser has no instruction to enforce HSTS. Therefore, including the header in HTTPS responses is essential for HSTS to take effect.
- ✗
The server must be configured to support TLS 1.2 or higher for HSTS to function.
Why it's wrong here
HSTS does not mandate a specific TLS version. It works with any HTTPS connection that the browser trusts. While using strong TLS versions is good practice, it is not a prerequisite for HSTS. The browser will enforce HTTPS as long as the initial connection is secure. Thus, this is not a required condition for HSTS effectiveness.
- ✗
The server must redirect all HTTP requests to HTTPS before the HSTS header is processed.
Why it's wrong here
While redirecting HTTP to HTTPS is a common practice, it is not a requirement for HSTS to be effective. HSTS works by instructing the browser to automatically use HTTPS for future requests, bypassing HTTP. The initial redirect is not necessary once HSTS is established; in fact, HSTS prevents the browser from even attempting HTTP. Thus, this is not a required condition.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.