ECCouncil Ethical Hacking and Countermeasures V8 EC0-350 Question # 205 Topic 21 Discussion

ECCouncil Ethical Hacking and Countermeasures V8 EC0-350 Question # 205 Topic 21 Discussion

EC0-350 Exam Topic 21 Question 205 Discussion:
Question #: 205
Topic #: 21

During a penetration test, a tester finds that the web application being analyzed is vulnerable to Cross Site Scripting (XSS). Which of the following conditions must be met to exploit this vulnerability?


A.

The web application does not have the secure flag set.


B.

The session cookies do not have the HttpOnly flag set.


C.

The victim user should not have an endpoint security solution.


D.

The victim's browser must have ActiveX technology enabled.


Get Premium EC0-350 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.