Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 4Objective 1

Cross-Site Request Forgery (CSRF) - GET and POST Methods WAHS Practice Questions (Page 3)

Part of the Request Forgery Attacks domain, which makes up ~6% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
6concepts

Questions 11–15

  1. 11expert · hard

    A penetration tester is evaluating the impact of a CSRF vulnerability in an application that allows users to change their shipping address. The application uses anti-CSRF tokens. The tester discovers that the token is generated based on the user's email address and is predictable. Which action should the tester take to exploit this?

    Select an answer first
  2. 12application · medium

    An attacker wants to perform CSRF against a user of a web application that changes the user's shipping address via a GET request. The user is currently authenticated. Which sequence of steps correctly describes the CSRF attack flow?

    Select an answer first
  3. 13application · medium

    A security analyst is assessing the impact of a CSRF vulnerability in a web application. The application allows users to update their profile information, including email address, via a GET request. Which of the following is the most likely impact of a successful CSRF attack?

    Select an answer first
  4. 14expert · hard

    A security architect is designing CSRF defenses for a multi-tenant web application. The application uses a shared domain for all tenants (e.g., app.example.com) and relies on session cookies. Some tenants require embedding the application in iframes on their own sites. Which CSRF defense would be most appropriate?

    Select an answer first
  5. 15expert · hard

    A web application uses anti-CSRF tokens that are stored in a cookie and also submitted as a hidden form field. The server validates that the cookie value matches the form value. An attacker finds a reflected XSS vulnerability in the same application. How does this affect CSRF protection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.