Cookie delivery depends on scope and attributes such as domain, path, Secure and SameSite. Server authentication must validate the received credential.
Before you start
You should understand clients, servers, IP addresses and ports. Follow a request through name resolution, connection establishment and application exchange. Distinguish protocol guarantees from deployment policy, and use observations from the relevant layer rather than guessing from one browser error message.
The practical goal is to reason through this situation: A cookie scoped to one path may not accompany another endpoint. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Choose delivery scope
Domain and path determine which requests receive the cookie.
Step 2: Use transport and access attributes
Secure and HttpOnly address different exposure mechanisms.
Step 3: Model ambient credentials
SameSite and CSRF strategy must match actual browser behavior.
Worked scenario
A cookie scoped to one path may not accompany another endpoint.
A session cookie scoped to /account may not accompany /api/orders, making a valid login appear absent there. HttpOnly prevents ordinary script access to the cookie but does not itself prevent the browser from sending it on every eligible request. The server still validates session expiry and authorization.
Common mistake
HttpOnly limits script access but does not independently prevent every forged request.
Verify the behavior
Test intended and unintended paths, secure transport, expiry and cross-site request behavior.
Interview exercise
Design a session cookie.
Answer and reasoning
Use deliberate transport and scope attributes, expiration and server validation, with a CSRF strategy matching browser delivery behavior.
Continue learning
Compare the scenario with the Networking interview questions and test your understanding with the Networking MCQs. For terminology and implementation details, consult the reference material.