Courseiva
Web Application Attacks →mediumMultiple Choice

PEN-200 Web Application Attacks Practice Question

Exhibit

HTTP/1.1 200 OK
Content-Type: text/html
Set-Cookie: session_id=abc123xyz; HttpOnly; Secure

<html><body>Welcome, User!</body></html>

Refer to the exhibit. An analyst observes this response header after a successful login. What is the security implication of the 'HttpOnly' and 'Secure' flags set on the 'session_id' cookie?

⚠ Common exam trap

Candidates often mix up the roles of 'HttpOnly' and 'Secure' flags, mistakenly thinking 'Secure' prevents XSS script access rather than mitigating cleartext network interception.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is protected against XSS theft and cleartext interception.

These security flags are critical for session hardening. 'HttpOnly' prevents client-side scripts from accessing the cookie via document.cookie, mitigating XSS-based session theft. 'Secure' ensures the cookie is only transmitted over encrypted HTTPS connections, preventing interception via man-in-the-middle attacks. Together, they provide a defense-in-depth layer protecting user session integrity, which is essential for maintaining secure authentication sessions against common web-based attacks during the post-authentication phase of an engagement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The flags guarantee protection against all SQL injection.

    Why it's wrong here

    Cookie flags only govern the transmission and access of the cookie itself. They have no impact on how the application handles input data or communicates with the backend database. SQL injection is a separate vulnerability category related to input validation, which remains unaffected by these specific browser cookie settings.

  • ✗

    The cookie will be accessible to JavaScript, but not via HTTP.

    Why it's wrong here

    The 'HttpOnly' flag does the exact opposite: it restricts cookie access from client-side scripts like JavaScript. It allows the browser to transmit the cookie during HTTP requests while preventing malicious scripts from reading the sensitive session identifier, which is a fundamental mitigation against session hijacking via cross-site scripting attacks.

  • ✓

    The session is protected against XSS theft and cleartext interception.

    Why this is correct

    The 'HttpOnly' attribute blocks access to the cookie from JavaScript, preventing XSS-based theft. The 'Secure' attribute ensures the browser only sends the cookie over encrypted HTTPS, preventing it from being intercepted in transit. These controls are standard security practices for mitigating session hijacking and credential exposure in web applications.

  • ✗

    The cookie will be automatically deleted when the browser closes.

    Why it's wrong here

    Cookie lifetime is determined by the 'Expires' or 'Max-Age' attributes. Without these, the cookie acts as a session cookie, but the 'HttpOnly' and 'Secure' flags do not define the persistence of the cookie. These flags focus exclusively on access control and transport security, not the duration of the cookie.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.