Courseiva

SSCP Systems and Application Security Practice Question

A security analyst is reviewing a web application that stores user session identifiers in cookies. The analyst wants to recommend cookie attributes that reduce the risk of session hijacking through cross-site scripting (XSS) and cross-site request forgery (CSRF). Which TWO of the following cookie attributes should the analyst recommend? (Choose two.)

⚠ Common exam trap

The trap here is selecting Secure as a mitigation for XSS, when Secure only protects cookies in transit and does not stop client-side script access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SameSite

HttpOnly prevents JavaScript from reading the session cookie, mitigating session theft via XSS. SameSite restricts the browser from sending the cookie on cross-site requests, mitigating CSRF. Together they address both threats named in the scenario. Secure, Domain, and Max-Age provide other benefits but do not directly counter XSS cookie theft or CSRF in the way the analyst requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Max-Age

    Why it's wrong here

    Max-Age sets the lifetime of the cookie in seconds. A shorter lifetime can limit the window of opportunity for a stolen session, but it does not prevent XSS from reading the cookie or CSRF from sending it. It is a session management consideration, not a direct mitigation for the two specific attack types in the scenario.

  • ✗

    Domain

    Why it's wrong here

    The Domain attribute specifies which hosts can receive the cookie. If set too broadly, it can expose the cookie to subdomains that may be less secure, increasing risk rather than reducing it. It does not prevent XSS from reading the cookie or CSRF from using it. Therefore, it is not a recommended mitigation for the threats described.

  • ✓

    SameSite

    Why this is correct

    The SameSite attribute controls whether the browser sends the cookie with cross-site requests. Setting SameSite to Lax or Strict prevents the cookie from being included in requests originating from other sites, which blocks CSRF attacks. This directly addresses the CSRF concern and complements HttpOnly for XSS protection, making it one of the two correct recommendations.

  • ✓

    HttpOnly

    Why this is correct

    The HttpOnly attribute prevents client-side scripts from accessing the cookie through the Document.cookie API. If an attacker successfully injects JavaScript via XSS, the script cannot read the session cookie, which significantly reduces the risk of session hijacking. This directly addresses the XSS concern in the scenario and is a standard recommendation for session cookies.

  • ✗

    Secure

    Why it's wrong here

    The Secure attribute ensures the cookie is only transmitted over HTTPS, protecting it from network eavesdropping. While important for confidentiality in transit, it does not prevent JavaScript from reading the cookie during an XSS attack, nor does it prevent CSRF. It is a valuable defense-in-depth measure but does not directly address the two threats named in the scenario.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.