
EC-CouncilWeb Application Hacking and Security
Domain 4Objective 1
Cross-Site Request Forgery (CSRF) - GET and POST Methods WAHS Practice Questions (Page 1)
Part of the Request Forgery Attacks domain, which makes up ~6% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
Questions 1–5
- 1
A security analyst is investigating a suspected CSRF attack. The application logs show a POST request to /change-password with valid session cookies and a valid anti-CSRF token. The request originated from an external IP. Which conclusion is most likely?
Select an answer first - 2
A security analyst is investigating a suspected CSRF attack. The application logs show a GET request to /user/email?new=attacker@example.com from the victim's IP address, and the email was changed. The victim claims they did not click any link. Which of the following is the most likely explanation?
Select an answer first - 3
Which types of web application functions are most likely to be targeted by CSRF attacks?
Select an answer first - 4
A company is deploying a new web application and must choose a CSRF defense. The application will be used by customers who often click links from external emails and sites. The team wants to minimize broken functionality while providing strong CSRF protection. Which approach is the best choice?
Select an answer first - 5
A development team is deciding on a CSRF defense for a web application that uses cookies for authentication. The application has both GET and POST state-changing endpoints. Which combination of defenses provides the strongest protection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.