Which action directly supports protection of cookies during transmission?

Prepare for the EC-Council Certified Security Specialist Exam with our comprehensive quiz. Enhance your understanding through flashcards and multiple-choice questions complete with hints and explanations. Boost your exam confidence today!

Multiple Choice

Which action directly supports protection of cookies during transmission?

Explanation:
Protecting cookies during transmission hinges on ensuring they are sent only over encrypted channels. The Secure attribute marks cookies as eligible to be sent exclusively over HTTPS, so when a TLS-encrypted request is made, the cookie is included; if the connection is plain HTTP, the cookie is not transmitted. This directly reduces the risk of cookies being intercepted by on-path attackers. Transmitting cookies over non-secure channels would expose them; making cookies accessible to JavaScript or storing them in local storage does not address how they are carried across the network and can introduce other security risks, even though those choices have their own concerns. So, setting the Secure flag on sensitive cookies best protects them during transmission.

Protecting cookies during transmission hinges on ensuring they are sent only over encrypted channels. The Secure attribute marks cookies as eligible to be sent exclusively over HTTPS, so when a TLS-encrypted request is made, the cookie is included; if the connection is plain HTTP, the cookie is not transmitted. This directly reduces the risk of cookies being intercepted by on-path attackers. Transmitting cookies over non-secure channels would expose them; making cookies accessible to JavaScript or storing them in local storage does not address how they are carried across the network and can introduce other security risks, even though those choices have their own concerns. So, setting the Secure flag on sensitive cookies best protects them during transmission.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy