Courseiva
Web Application Attacks →mediumMultiple Choice

PEN-200 Web Application Attacks Practice Question

Which of the following is the most effective way to prevent Cross-Site Scripting (XSS) in a web application?

⚠ Common exam trap

Test-takers frequently select input validation or sanitization instead of context-aware output encoding, misunderstanding that prevention must occur when data is rendered in the browser.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing context-aware output encoding for all user-supplied data.

The most effective defense against XSS is context-aware output encoding. By converting special characters into their HTML entity equivalents before rendering, you ensure the browser treats the input as data rather than executable code. This is a critical security practice because it handles the root cause of the vulnerability—the browser's inability to distinguish between intended content and injected malicious scripts, regardless of the user input provided.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using a blacklist to filter out common JavaScript keywords.

    Why it's wrong here

    Blacklisting is an ineffective defense because attackers can easily bypass it using alternative encodings, casing, or obfuscation. Relying on a list of 'bad' words is a flawed security strategy because it cannot anticipate all possible malicious payloads that might be used by a sophisticated attacker.

  • ✓

    Implementing context-aware output encoding for all user-supplied data.

    Why this is correct

    Context-aware encoding ensures that data is neutralized based on where it is displayed—HTML body, attribute, or JavaScript. By correctly encoding characters like '<', '>', and quotes, the browser is instructed to display the input literally rather than executing it, which is the standard defensive requirement.

  • ✗

    Disabling all JavaScript in the user's browser settings.

    Why it's wrong here

    This is a client-side configuration, not a server-side security measure. A secure application must protect all users, including those who need JavaScript enabled. Relying on end-users to secure their own environment is not a valid security strategy for a robust and professional web application.

  • ✗

    Setting all cookies with the 'Secure' flag in the response header.

    Why it's wrong here

    The 'Secure' flag protects cookies during transport over HTTPS; it does not prevent XSS. While it is an important security setting, it does not stop the execution of malicious scripts on the client's machine, which is the objective of an XSS attack, making it an irrelevant defense here.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.