Certified Ethical Hacker CEH · Free Practice Question Easy

Question 47

Cross site request forgery (CSRF) attack is successful only if:
  • A A. User provides password to attacker
  • B B. User clicks on malicious website or link
  • C C. User uses unsecured network
  • D D. User is not connected to the network
Reveal correct answer

Correct answer: B

Explanation

Correct Answer: B. user clicks on malicious website or link Explanation: Cross-Site Request Forgery (CSRF) is a type of cyber-attack where an attacker tricks a user's web browser into making a request to another website without the user's knowledge or consent. For example, a user is logged in to the bank's website and then he visits a malicious website. The malicious website could contain hidden code that sends a request to the user's bank website to transfer money from the user account to the attacker's account. Since the user is already logged in to the bank's website, the request would be sent with the user's credentials and the transaction would appear to be authorized by the user.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need