Courseiva

GSEC Web Communication Security Practice Question

A web developer is implementing a new session management system and wants to ensure that session cookies are not accessible via JavaScript to mitigate cross-site scripting (XSS) attacks. Which cookie attribute should be set?

⚠ Common exam trap

It's easy for candidates to confuse the Secure attribute with HttpOnly; Secure protects transmission, not JavaScript access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HttpOnly

The HttpOnly attribute is specifically designed to prevent client-side scripts from accessing cookies. By setting HttpOnly, the cookie is protected from theft via XSS attacks that execute JavaScript in the victim's browser. The other attributes serve different purposes: Secure ensures HTTPS transmission, SameSite mitigates CSRF, and Domain controls cookie scope. Only HttpOnly directly addresses the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SameSite

    Why it's wrong here

    The SameSite attribute controls when cookies are sent with cross-site requests, helping to prevent CSRF attacks. It does not restrict JavaScript access to the cookie. While important for security, it does not address the specific risk of XSS reading the cookie. Thus, it is not the correct choice for preventing JavaScript access.

  • ✗

    Domain

    Why it's wrong here

    The Domain attribute specifies which hosts can receive the cookie. It does not affect JavaScript accessibility. Setting the Domain attribute can broaden or narrow the scope of the cookie, but it does not prevent XSS from reading it. Therefore, it does not meet the requirement of blocking JavaScript access to the session cookie.

  • ✓

    HttpOnly

    Why this is correct

    The HttpOnly attribute instructs the browser to prevent client-side scripts from accessing the cookie. This directly mitigates XSS attacks that attempt to steal session cookies via document.cookie. When set, the cookie is only accessible to the server, not JavaScript. This is the correct attribute to use for the described requirement.

  • ✗

    Secure

    Why it's wrong here

    The Secure attribute ensures the cookie is only sent over HTTPS, protecting it from interception over unencrypted channels. However, it does not prevent JavaScript from accessing the cookie. An XSS attack could still read the cookie via document.cookie if the Secure attribute is the only protection. Therefore, Secure alone does not mitigate the risk described.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.