
EC-CouncilWeb Application Hacking and Security
Domain 4Objective 1
Cross-Site Request Forgery (CSRF) - GET and POST Methods WAHS Practice Questions (Page 4)
Part of the Request Forgery Attacks domain, which makes up ~6% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
Questions 16–20
- 16
Which statement best describes how a CSRF attack occurs?
Select an answer first - 17
A development team is migrating a legacy application that uses GET requests for state changes to a modern framework. They want to implement CSRF protection with minimal code changes. Which approach is most effective?
Select an answer first - 18
A user is logged into a web application that allows changing account details via GET requests. The user visits a forum where an attacker has posted a message with an <img> tag pointing to a URL that changes the user's email. The user's email is changed. Which statement best describes why this attack succeeded?
Select an answer first - 19
Which of the following is a potential impact of a successful CSRF attack?
Select an answer first - 20
How does an attacker execute a POST-based CSRF attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.