exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 269 discussion

Actual exam question from ISC's CISSP
Question #: 269
Topic #: 1
[All CISSP Questions]

Which of the following types of web-based attack is happening when an attacker is able to send a well-crafted, malicious request to an authenticated user realizing it?

  • A. Process injection
  • B. Cross-Site request forgery (CSRF)
  • C. Cross-Site Scripting (XSS)
  • D. Broken Authentication And Session Management
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rdy4u
Highly Voted 10 months, 2 weeks ago
Selected Answer: B
Cross-site scripting (or XSS) allows an attacker to execute arbitrary JavaScript within the browser of a victim user. Cross-site request forgery (or CSRF) allows an attacker to induce a victim user to perform actions that they do not intend to.
upvoted 6 times
jackdryan
3 months, 4 weeks ago
B is correct
upvoted 1 times
...
...
franbarpro
Most Recent 10 months, 3 weeks ago
Selected Answer: B
The "malicious request to an authenticated user" = to **B. Cross-Site request forgery (CSRF)**
upvoted 2 times
...
JAckThePip
11 months, 1 week ago
Answer is correct "CSRF occurs when a hacker is able to send a well-crafted, yet malicious, request to an authenticated user that includes the necessary parameters (variables) to complete a valid application request without the victim (user) ever realizing it." https://www.sciencedirect.com/topics/computer-science/malicious-request
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago