PEN-200 Client-Side Attacks Practice Question
You are testing a web application that sets a session cookie with the HttpOnly flag. You find a reflected XSS vulnerability on a page that does not require authentication. What is the primary impact of exploiting this XSS given the HttpOnly flag?
⚠ Common exam trap
The trap here is equating HttpOnly with complete protection against XSS, when it only blocks direct cookie theft via document.cookie.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
You can execute arbitrary JavaScript in the victim’s browser to perform actions as the victim, but you cannot directly read the session cookie via document.cookie.
HttpOnly is designed to prevent client-side scripts from reading cookie values, but it does not prevent script execution or stop the browser from sending the cookie with requests. An attacker who achieves XSS can still act as the victim by issuing requests, reading page content, or capturing keystrokes. The session cookie may be inaccessible to document.cookie, but the authenticated session remains exploitable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
You can read the session cookie using document.cookie because HttpOnly only applies to cookies set over HTTPS.
Why it's wrong here
HttpOnly is independent of the Secure flag. It restricts access to the cookie from JavaScript APIs such as document.cookie regardless of whether the connection uses HTTPS. A cookie can be both Secure and HttpOnly, but Secure alone governs transport, while HttpOnly alone governs script access. This option confuses the two attributes and would not allow cookie theft here.
- ✗
You can bypass HttpOnly by using XMLHttpRequest to fetch the cookie from the server’s response headers.
Why it's wrong here
HttpOnly cookies are never exposed to JavaScript, including through XMLHttpRequest or fetch. The browser automatically attaches them to same-origin requests, but the Set-Cookie and Cookie headers are not readable by script. You cannot retrieve the cookie value from response headers, so this technique does not defeat the protection.
- ✗
You cannot execute JavaScript at all because HttpOnly blocks all script execution on the page.
Why it's wrong here
HttpOnly only affects cookie access from JavaScript; it does not disable JavaScript execution. The XSS payload still runs in the victim’s browser and can perform a wide range of actions. The flag is a mitigation for cookie theft, not a general script blocker. This option overstates the protection and would lead a tester to incorrectly dismiss a valid XSS finding.
- ✓
You can execute arbitrary JavaScript in the victim’s browser to perform actions as the victim, but you cannot directly read the session cookie via document.cookie.
Why this is correct
HttpOnly prevents JavaScript from accessing the cookie through document.cookie, but it does not stop script execution. The attacker can still issue authenticated requests from the victim’s browser, read page content, log keystrokes, or manipulate the DOM. The session remains usable by the browser automatically, so actions can be performed on behalf of the victim even though the cookie value cannot be stolen directly.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.