PEN-200 Web Application Attacks Practice Question
You are testing an e-commerce application that uses a cookie named 'sessionid' to maintain authenticated sessions. The application sets this cookie without the HttpOnly attribute, and you have identified a reflected XSS vulnerability in the product search feature. Which of the following attack methods would allow you to steal the session cookie and hijack an authenticated user's session?
⚠ Common exam trap
Test-takers frequently confuse session hijacking via cookie theft with other client-side attacks like CSRF or phishing, which do not require reading the cookie value.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inject a script that reads document.cookie and sends it to an attacker-controlled server.
When a session cookie lacks the HttpOnly attribute, client-side JavaScript can access it through document.cookie. A reflected XSS vulnerability allows an attacker to inject and execute arbitrary script in the victim's browser, which can then read the cookie and exfiltrate it. The stolen session identifier can be used to impersonate the authenticated user. Other attacks like redirects, fake forms, or CSRF do not directly steal the cookie.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Inject a script that reads document.cookie and sends it to an attacker-controlled server.
Why this is correct
Because the sessionid cookie lacks the HttpOnly flag, JavaScript running in the page context can access it via document.cookie. By injecting a script through the reflected XSS vulnerability, the attacker can read the cookie value and exfiltrate it to a server they control. The stolen sessionid can then be used to impersonate the victim and hijack the authenticated session. This directly exploits the missing HttpOnly attribute combined with XSS.
- ✗
Inject a script that calls window.location = 'https://attacker.com' to redirect the user.
Why it's wrong here
Redirecting the user to an attacker-controlled site does not directly steal the session cookie. While it may facilitate phishing or other attacks, it does not read or transmit the cookie value. In this scenario, the goal is to hijack the session by obtaining the sessionid, which requires reading document.cookie. A simple redirect does not accomplish that, so this method fails to achieve session hijacking.
- ✗
Inject a script that triggers a CSRF request to change the user's password.
Why it's wrong here
A CSRF attack forces the victim's browser to send an authenticated request, but it does not read the session cookie. The attacker does not learn the sessionid and cannot directly hijack the session. While CSRF can be impactful, it is a different vulnerability class and does not leverage the missing HttpOnly flag to steal the cookie. In this scenario, the objective is session hijacking via cookie theft, which requires reading document.cookie.
- ✗
Inject a script that modifies the DOM to display a fake login form.
Why it's wrong here
Displaying a fake login form is a form of UI redressing or phishing, but it does not steal the existing session cookie. The attacker would need the user to enter credentials, which is less reliable and does not directly exploit the missing HttpOnly flag. In this scenario, the sessionid is already present and accessible via JavaScript, so a fake form is unnecessary and does not hijack the session.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.