PEN-200 Web Application Attacks Practice Question
Exhibit
Refer to the exhibit: [Response Header] Set-Cookie: session_id=abc123; HttpOnly; SameSite=Strict
Which of the following describes the security benefit of the 'HttpOnly' flag shown in the exhibit?
⚠ Common exam trap
Candidates often confuse HttpOnly with Secure flags, incorrectly believing that HttpOnly prevents man-in-the-middle attacks or encrypts the cookie, rather than specifically restricting client-side script access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It prevents the cookie from being accessed by JavaScript.
The 'HttpOnly' flag prevents client-side scripts from accessing the cookie via the document.cookie API. This is a crucial defense against session hijacking attacks, as it ensures that even if an attacker successfully executes a Cross-Site Scripting (XSS) payload, they cannot steal the session identifier. This protection layer is a standard security configuration for sensitive session cookies in modern web applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It ensures the cookie is only sent over encrypted HTTPS connections.
Why it's wrong here
This is the function of the 'Secure' flag, not 'HttpOnly'. While both are important security controls, the 'Secure' flag manages transport encryption, whereas 'HttpOnly' specifically mitigates access from client-side scripts, keeping the cookie inaccessible to malicious JavaScript payloads.
- ✓
It prevents the cookie from being accessed by JavaScript.
Why this is correct
The 'HttpOnly' attribute is specifically designed to block access to the cookie through the document.cookie property. This protects the session from being stolen by XSS attacks, as malicious scripts are unable to read or transmit the session token to an attacker-controlled server.
- ✗
It stops the browser from sending the cookie in cross-site requests.
Why it's wrong here
This behavior is controlled by the 'SameSite' attribute, as shown in the exhibit. While 'SameSite=Strict' provides protection against CSRF, 'HttpOnly' is concerned with preventing script-based access to the cookie, making this option incorrect for the specific role of the 'HttpOnly' flag.
- ✗
It automatically regenerates the session ID every 30 minutes.
Why it's wrong here
Session expiration and regeneration are server-side session management policies, not browser-side cookie attributes. The 'HttpOnly' flag is a security instruction to the browser regarding access, not a policy governing the lifecycle or refresh rate of the session token on the server.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.