ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A tax-filing company discovers that some customers still access its public web portal with old http:// bookmarks, exposing personally identifiable information during the initial connection and making the site vulnerable to SSL-stripping attacks. As the newly hired security administrator, you must ensure that every future browser request- including the very first one- is automatically upgraded to HTTPS without requiring users to change their behavior. Which action best satisfies this requirement?
Replace the existing certificate with an Extended Validation (EV) certificate from a trusted public certificate authority.
Implement HTTP Strict Transport Security (HSTS) with a one-year max-age and add the domain to the HSTS preload lists so browsers always initiate HTTPS connections.
Configure the web server to issue permanent (301) redirects from http:// to https:// for all incoming requests.
Disable TLS 1.0 and 1.1 on the server, allowing only TLS 1.2 and TLS 1.3 with modern cipher suites.
Enabling HTTP Strict Transport Security (HSTS) with a long max-age and submitting the domain to the browser vendors' preload lists instructs compliant browsers to connect only over HTTPS, even for the very first request, and blocks protocol-downgrade or SSL-stripping attempts. A simple 301 redirect still allows attackers to intercept the initial HTTP request. Merely disabling older TLS versions improves cipher strength but does not stop browsers from attempting an unencrypted connection. Extended Validation certificates add identity assurance but provide no automatic upgrade or stripping protection.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is HSTS and how does it enforce HTTPS?
Open an interactive chat with Bash
What are the HSTS preload lists, and why are they important?
Open an interactive chat with Bash
How does SSL-stripping work, and how does HSTS prevent it?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .