PEN-200 Web Application Attacks Practice Question
Exhibit
HTTP/1.1 200 OK Content-Type: text/html Set-Cookie: session_id=abc123xyz; HttpOnly; Secure <html><body>Welcome, User!</body></html>
Refer to the exhibit. An analyst observes this response header after a successful login. What is the security implication of the 'HttpOnly' and 'Secure' flags set on the 'session_id' cookie?
⚠ Common exam trap
Candidates often mix up the roles of 'HttpOnly' and 'Secure' flags, mistakenly thinking 'Secure' prevents XSS script access rather than mitigating cleartext network interception.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session is protected against XSS theft and cleartext interception.
These security flags are critical for session hardening. 'HttpOnly' prevents client-side scripts from accessing the cookie via document.cookie, mitigating XSS-based session theft. 'Secure' ensures the cookie is only transmitted over encrypted HTTPS connections, preventing interception via man-in-the-middle attacks. Together, they provide a defense-in-depth layer protecting user session integrity, which is essential for maintaining secure authentication sessions against common web-based attacks during the post-authentication phase of an engagement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The flags guarantee protection against all SQL injection.
Why it's wrong here
Cookie flags only govern the transmission and access of the cookie itself. They have no impact on how the application handles input data or communicates with the backend database. SQL injection is a separate vulnerability category related to input validation, which remains unaffected by these specific browser cookie settings.
- ✗
The cookie will be accessible to JavaScript, but not via HTTP.
Why it's wrong here
The 'HttpOnly' flag does the exact opposite: it restricts cookie access from client-side scripts like JavaScript. It allows the browser to transmit the cookie during HTTP requests while preventing malicious scripts from reading the sensitive session identifier, which is a fundamental mitigation against session hijacking via cross-site scripting attacks.
- ✓
The session is protected against XSS theft and cleartext interception.
Why this is correct
The 'HttpOnly' attribute blocks access to the cookie from JavaScript, preventing XSS-based theft. The 'Secure' attribute ensures the browser only sends the cookie over encrypted HTTPS, preventing it from being intercepted in transit. These controls are standard security practices for mitigating session hijacking and credential exposure in web applications.
- ✗
The cookie will be automatically deleted when the browser closes.
Why it's wrong here
Cookie lifetime is determined by the 'Expires' or 'Max-Age' attributes. Without these, the cookie acts as a session cookie, but the 'HttpOnly' and 'Secure' flags do not define the persistence of the cookie. These flags focus exclusively on access control and transport security, not the duration of the cookie.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.