A security analyst is examining a web application that uses HTTP Strict Transport Security (HSTS). The analyst notices that the HSTS header is only sent on HTTPS responses and includes the 'preload' directive. Which additional measure must be taken to ensure the domain is included in browser preload lists?
To be included in browser HSTS preload lists, the domain must be submitted to the preload list service (e.g., hstspreload.org) and meet specific requirements: the HSTS header must include 'includeSubDomains', 'preload', and a max-age of at least 31536000 seconds (one year). The preload directive signals intent, but submission is a separate manual step. This ensures the domain is hardcoded into browsers, providing protection even on the first visit.
Why this answer
To preload HSTS, the domain must meet strict criteria: the HSTS header must include 'includeSubDomains', 'preload', and a max-age of at least one year. The 'preload' directive alone does not trigger automatic inclusion; the domain must be submitted to the preload list service. Once accepted, browsers hardcode the domain, enforcing HTTPS even on the first visit.
This prevents SSL stripping attacks during initial connections.
Exam trap
The trap here is assuming that adding the 'preload' directive to the HSTS header is sufficient for browser preloading, when in fact manual submission and specific header requirements must be satisfied.