SSCP Systems and Application Security Practice Question
A security analyst is reviewing a web application that stores user session identifiers in cookies. The analyst wants to recommend cookie attributes that reduce the risk of session hijacking through cross-site scripting (XSS) and cross-site request forgery (CSRF). Which TWO of the following cookie attributes should the analyst recommend? (Choose two.)
⚠ Common exam trap
The trap here is selecting Secure as a mitigation for XSS, when Secure only protects cookies in transit and does not stop client-side script access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SameSite
HttpOnly prevents JavaScript from reading the session cookie, mitigating session theft via XSS. SameSite restricts the browser from sending the cookie on cross-site requests, mitigating CSRF. Together they address both threats named in the scenario. Secure, Domain, and Max-Age provide other benefits but do not directly counter XSS cookie theft or CSRF in the way the analyst requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Max-Age
Why it's wrong here
Max-Age sets the lifetime of the cookie in seconds. A shorter lifetime can limit the window of opportunity for a stolen session, but it does not prevent XSS from reading the cookie or CSRF from sending it. It is a session management consideration, not a direct mitigation for the two specific attack types in the scenario.
- ✗
Domain
Why it's wrong here
The Domain attribute specifies which hosts can receive the cookie. If set too broadly, it can expose the cookie to subdomains that may be less secure, increasing risk rather than reducing it. It does not prevent XSS from reading the cookie or CSRF from using it. Therefore, it is not a recommended mitigation for the threats described.
- ✓
SameSite
Why this is correct
The SameSite attribute controls whether the browser sends the cookie with cross-site requests. Setting SameSite to Lax or Strict prevents the cookie from being included in requests originating from other sites, which blocks CSRF attacks. This directly addresses the CSRF concern and complements HttpOnly for XSS protection, making it one of the two correct recommendations.
- ✓
HttpOnly
Why this is correct
The HttpOnly attribute prevents client-side scripts from accessing the cookie through the Document.cookie API. If an attacker successfully injects JavaScript via XSS, the script cannot read the session cookie, which significantly reduces the risk of session hijacking. This directly addresses the XSS concern in the scenario and is a standard recommendation for session cookies.
- ✗
Secure
Why it's wrong here
The Secure attribute ensures the cookie is only transmitted over HTTPS, protecting it from network eavesdropping. While important for confidentiality in transit, it does not prevent JavaScript from reading the cookie during an XSS attack, nor does it prevent CSRF. It is a valuable defense-in-depth measure but does not directly address the two threats named in the scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.