Courseiva
Client-Side Attacks →hardMultiple Choice

PEN-200 Client-Side Attacks Practice Question

You are testing a web application that sets a session cookie with the HttpOnly flag. You find a reflected XSS vulnerability on a page that does not require authentication. What is the primary impact of exploiting this XSS given the HttpOnly flag?

⚠ Common exam trap

The trap here is equating HttpOnly with complete protection against XSS, when it only blocks direct cookie theft via document.cookie.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

You can execute arbitrary JavaScript in the victim’s browser to perform actions as the victim, but you cannot directly read the session cookie via document.cookie.

HttpOnly is designed to prevent client-side scripts from reading cookie values, but it does not prevent script execution or stop the browser from sending the cookie with requests. An attacker who achieves XSS can still act as the victim by issuing requests, reading page content, or capturing keystrokes. The session cookie may be inaccessible to document.cookie, but the authenticated session remains exploitable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    You can read the session cookie using document.cookie because HttpOnly only applies to cookies set over HTTPS.

    Why it's wrong here

    HttpOnly is independent of the Secure flag. It restricts access to the cookie from JavaScript APIs such as document.cookie regardless of whether the connection uses HTTPS. A cookie can be both Secure and HttpOnly, but Secure alone governs transport, while HttpOnly alone governs script access. This option confuses the two attributes and would not allow cookie theft here.

  • ✗

    You can bypass HttpOnly by using XMLHttpRequest to fetch the cookie from the server’s response headers.

    Why it's wrong here

    HttpOnly cookies are never exposed to JavaScript, including through XMLHttpRequest or fetch. The browser automatically attaches them to same-origin requests, but the Set-Cookie and Cookie headers are not readable by script. You cannot retrieve the cookie value from response headers, so this technique does not defeat the protection.

  • ✗

    You cannot execute JavaScript at all because HttpOnly blocks all script execution on the page.

    Why it's wrong here

    HttpOnly only affects cookie access from JavaScript; it does not disable JavaScript execution. The XSS payload still runs in the victim’s browser and can perform a wide range of actions. The flag is a mitigation for cookie theft, not a general script blocker. This option overstates the protection and would lead a tester to incorrectly dismiss a valid XSS finding.

  • ✓

    You can execute arbitrary JavaScript in the victim’s browser to perform actions as the victim, but you cannot directly read the session cookie via document.cookie.

    Why this is correct

    HttpOnly prevents JavaScript from accessing the cookie through document.cookie, but it does not stop script execution. The attacker can still issue authenticated requests from the victim’s browser, read page content, log keystrokes, or manipulate the DOM. The session remains usable by the browser automatically, so actions can be performed on behalf of the victim even though the cookie value cannot be stolen directly.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.