Courseiva
Web Application Attacks →mediumMultiple Choice

PEN-200 Web Application Attacks Practice Question

Exhibit

Refer to the exhibit: 
[Response Header]
Set-Cookie: session_id=abc123; HttpOnly; SameSite=Strict

Which of the following describes the security benefit of the 'HttpOnly' flag shown in the exhibit?

⚠ Common exam trap

Candidates often confuse HttpOnly with Secure flags, incorrectly believing that HttpOnly prevents man-in-the-middle attacks or encrypts the cookie, rather than specifically restricting client-side script access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It prevents the cookie from being accessed by JavaScript.

The 'HttpOnly' flag prevents client-side scripts from accessing the cookie via the document.cookie API. This is a crucial defense against session hijacking attacks, as it ensures that even if an attacker successfully executes a Cross-Site Scripting (XSS) payload, they cannot steal the session identifier. This protection layer is a standard security configuration for sensitive session cookies in modern web applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It ensures the cookie is only sent over encrypted HTTPS connections.

    Why it's wrong here

    This is the function of the 'Secure' flag, not 'HttpOnly'. While both are important security controls, the 'Secure' flag manages transport encryption, whereas 'HttpOnly' specifically mitigates access from client-side scripts, keeping the cookie inaccessible to malicious JavaScript payloads.

  • ✓

    It prevents the cookie from being accessed by JavaScript.

    Why this is correct

    The 'HttpOnly' attribute is specifically designed to block access to the cookie through the document.cookie property. This protects the session from being stolen by XSS attacks, as malicious scripts are unable to read or transmit the session token to an attacker-controlled server.

  • ✗

    It stops the browser from sending the cookie in cross-site requests.

    Why it's wrong here

    This behavior is controlled by the 'SameSite' attribute, as shown in the exhibit. While 'SameSite=Strict' provides protection against CSRF, 'HttpOnly' is concerned with preventing script-based access to the cookie, making this option incorrect for the specific role of the 'HttpOnly' flag.

  • ✗

    It automatically regenerates the session ID every 30 minutes.

    Why it's wrong here

    Session expiration and regeneration are server-side session management policies, not browser-side cookie attributes. The 'HttpOnly' flag is a security instruction to the browser regarding access, not a policy governing the lifecycle or refresh rate of the session token on the server.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.