Courseiva
Web Communication Security →mediumMultiple Choice

GSEC Web Communication Security Practice Question

Exhibit

HTTP/1.1 200 OK
Set-Cookie: session_id=12345; HttpOnly; Secure
Content-Type: text/html

Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?

⚠ Common exam trap

Candidates often confuse the HttpOnly flag with the Secure flag, incorrectly believing HttpOnly prevents interception over unencrypted networks rather than preventing script access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cross-Site Scripting (XSS) session theft

The HttpOnly flag is a vital defense against session hijacking via XSS. When this flag is enabled, the browser prevents client-side scripts, such as JavaScript, from accessing the cookie via the document.cookie object. If an attacker successfully executes an XSS attack, they cannot steal the session cookie, thereby preventing them from impersonating the user's session. This is a core defense-in-depth practice for protecting authentication tokens in modern web applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-Site Request Forgery (CSRF)

    Why it's wrong here

    CSRF attacks rely on the browser automatically including cookies in cross-site requests. HttpOnly does not stop this behavior. To prevent CSRF, developers should use anti-CSRF tokens or the SameSite cookie attribute, as these mechanisms specifically target the request context rather than script-based access to stored cookies.

  • ✓

    Cross-Site Scripting (XSS) session theft

    Why this is correct

    HttpOnly prevents JavaScript from reading the cookie content. In an XSS scenario, an attacker typically tries to exfiltrate the session cookie to an external server. With the HttpOnly attribute, the browser rejects requests from scripts to read the cookie, effectively neutralizing this specific theft vector during an injection.

  • ✗

    Man-in-the-Middle (MitM) interception

    Why it's wrong here

    MitM interception is prevented by transport encryption, such as TLS/HTTPS. The Secure flag handles the requirement for encryption. The HttpOnly flag is strictly concerned with preventing client-side script access to cookie data and has no effect on network-level visibility or interception of data during transit.

  • ✗

    SQL Injection (SQLi)

    Why it's wrong here

    SQL injection occurs when untrusted user input is directly processed by a database query. This is a server-side vulnerability unrelated to how a browser stores or manages cookies. HttpOnly is a browser-side protection mechanism and provides no mitigation for database-level input validation or command execution vulnerabilities.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.