Question 1
Q1A financial organization is deploying a new web application through BIG-IP APM and requires stringent protection against cookie hijacking. The security team mandates that session cookies must not be accessible via client-side scripts and must only be transmitted over encrypted channels. Which combination of APM cookie settings will fulfill these requirements?
Show answer & explanation
Correct answer: B
To mitigate cookie hijacking, the 'HttpOnly' attribute prevents client-side scripts (like JavaScript) from accessing the session cookie, mitigating Cross-Site Scripting (XSS) risks. The 'Secure' attribute ensures the browser only transmits the cookie over HTTPS connections, protecting it from being intercepted in plain text over unencrypted networks.