Which cookie value or attribute helps protect session tokens from a cross-site scripting attack?
HTTP-ONLY is set
Domain is not set
Expiration is set to one week
Expiration is set to one day