PEN-200 Web Application Attacks Practice Question
Which of the following is the most effective way to prevent Cross-Site Scripting (XSS) in a web application?
⚠ Common exam trap
Test-takers frequently select input validation or sanitization instead of context-aware output encoding, misunderstanding that prevention must occur when data is rendered in the browser.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing context-aware output encoding for all user-supplied data.
The most effective defense against XSS is context-aware output encoding. By converting special characters into their HTML entity equivalents before rendering, you ensure the browser treats the input as data rather than executable code. This is a critical security practice because it handles the root cause of the vulnerability—the browser's inability to distinguish between intended content and injected malicious scripts, regardless of the user input provided.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a blacklist to filter out common JavaScript keywords.
Why it's wrong here
Blacklisting is an ineffective defense because attackers can easily bypass it using alternative encodings, casing, or obfuscation. Relying on a list of 'bad' words is a flawed security strategy because it cannot anticipate all possible malicious payloads that might be used by a sophisticated attacker.
- ✓
Implementing context-aware output encoding for all user-supplied data.
Why this is correct
Context-aware encoding ensures that data is neutralized based on where it is displayed—HTML body, attribute, or JavaScript. By correctly encoding characters like '<', '>', and quotes, the browser is instructed to display the input literally rather than executing it, which is the standard defensive requirement.
- ✗
Disabling all JavaScript in the user's browser settings.
Why it's wrong here
This is a client-side configuration, not a server-side security measure. A secure application must protect all users, including those who need JavaScript enabled. Relying on end-users to secure their own environment is not a valid security strategy for a robust and professional web application.
- ✗
Setting all cookies with the 'Secure' flag in the response header.
Why it's wrong here
The 'Secure' flag protects cookies during transport over HTTPS; it does not prevent XSS. While it is an important security setting, it does not stop the execution of malicious scripts on the client's machine, which is the objective of an XSS attack, making it an irrelevant defense here.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.