GSEC Web Communication Security Practice Question
Exhibit
HTTP/1.1 200 OK Set-Cookie: session_id=12345; HttpOnly; Secure Content-Type: text/html
Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?
⚠ Common exam trap
Candidates often confuse the HttpOnly flag with the Secure flag, incorrectly believing HttpOnly prevents interception over unencrypted networks rather than preventing script access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cross-Site Scripting (XSS) session theft
The HttpOnly flag is a vital defense against session hijacking via XSS. When this flag is enabled, the browser prevents client-side scripts, such as JavaScript, from accessing the cookie via the document.cookie object. If an attacker successfully executes an XSS attack, they cannot steal the session cookie, thereby preventing them from impersonating the user's session. This is a core defense-in-depth practice for protecting authentication tokens in modern web applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-Site Request Forgery (CSRF)
Why it's wrong here
CSRF attacks rely on the browser automatically including cookies in cross-site requests. HttpOnly does not stop this behavior. To prevent CSRF, developers should use anti-CSRF tokens or the SameSite cookie attribute, as these mechanisms specifically target the request context rather than script-based access to stored cookies.
- ✓
Cross-Site Scripting (XSS) session theft
Why this is correct
HttpOnly prevents JavaScript from reading the cookie content. In an XSS scenario, an attacker typically tries to exfiltrate the session cookie to an external server. With the HttpOnly attribute, the browser rejects requests from scripts to read the cookie, effectively neutralizing this specific theft vector during an injection.
- ✗
Man-in-the-Middle (MitM) interception
Why it's wrong here
MitM interception is prevented by transport encryption, such as TLS/HTTPS. The Secure flag handles the requirement for encryption. The HttpOnly flag is strictly concerned with preventing client-side script access to cookie data and has no effect on network-level visibility or interception of data during transit.
- ✗
SQL Injection (SQLi)
Why it's wrong here
SQL injection occurs when untrusted user input is directly processed by a database query. This is a server-side vulnerability unrelated to how a browser stores or manages cookies. HttpOnly is a browser-side protection mechanism and provides no mitigation for database-level input validation or command execution vulnerabilities.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.