CEH Web Application and Injection Attacks Practice Question
Which TWO of the following are effective defenses against Cross-Site Request Forgery (CSRF) attacks? (Select 2)
⚠ Common exam trap
CEH often tests the confusion between CSRF defenses and XSS/injection defenses, trapping candidates who pick HSTS, CSP, or input validation as CSRF mitigations when they address different threat models.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using anti-CSRF tokens
Option A (Using anti-CSRF tokens) is correct because a unique, unpredictable token tied to the user's session and validated server-side ensures that a forged request originating from a malicious third-party site cannot include the correct token, so the request is rejected. Option B (Setting the SameSite attribute on cookies) is correct because SameSite=Lax or SameSite=Strict prevents the browser from attaching session cookies to cross-site requests, which blocks the automatic credential submission that CSRF relies on. Option C (HSTS) is not correct because it only enforces HTTPS and prevents protocol downgrade/SSL-stripping attacks, not cross-site request forgery. Option D (input validation) is not correct because validating input addresses injection flaws like XSS or SQLi but does not stop a browser from sending an authenticated forged request. Option E (CSP headers) is not correct because CSP mitigates XSS and content-injection risks, which is a different attack class than CSRF.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using anti-CSRF tokens
Why this is correct
Anti-CSRF tokens are unique, unpredictable, secret values generated by the server and embedded into forms or AJAX requests. When a user submits a request, the server verifies that the token received matches the one issued for that specific session. This mechanism prevents attackers from forging requests, as they cannot predict or obtain the valid token required for a successful submission from the legitimate user's browser session. Without a valid token, the server rejects the request, effectively blocking the CSRF attack.
- ✓
Setting the SameSite attribute on cookies
Why this is correct
The `SameSite` attribute on cookies instructs web browsers to restrict when cookies are sent with cross-site requests. By setting this attribute to `Lax` or `Strict`, the browser will prevent the session cookie from being automatically included in third-party contexts, such as an attacker's malicious website making a request to the legitimate site. This significantly mitigates CSRF by ensuring that authentication credentials, typically stored in session cookies, are not inadvertently sent with requests originating from different domains.
- ✗
Enabling HTTP Strict Transport Security (HSTS)
Why it's wrong here
HTTP Strict Transport Security (HSTS) is a security policy mechanism that helps protect websites against downgrade attacks and cookie hijacking by forcing browsers to interact with the server only over HTTPS. While crucial for enforcing encrypted communication and preventing man-in-the-middle attacks, HSTS does not prevent Cross-Site Request Forgery (CSRF). A CSRF attack exploits the browser's trust in a user's authenticated session, regardless of whether the communication is encrypted, meaning a forged request sent over HTTPS would still be processed if the session cookie is included.
- ✗
Implementing input validation on all user inputs
Why it's wrong here
Input validation is a critical security measure designed to ensure that data submitted by users conforms to expected formats and types, preventing vulnerabilities like SQL injection or Cross-Site Scripting (XSS). However, it does not directly defend against Cross-Site Request Forgery (CSRF) attacks. CSRF exploits the browser's automatic inclusion of session cookies with requests to a trusted site, not malformed input. A valid, but unauthorized, request initiated by an attacker through the victim's browser would still pass input validation checks.
- ✗
Using Content Security Policy (CSP) headers
Why it's wrong here
Content Security Policy (CSP) is a security mechanism that helps mitigate various types of attacks, primarily Cross-Site Scripting (XSS), by specifying which content sources (e.g., scripts, stylesheets, images) are permitted to be loaded and executed by the browser. While highly effective against client-side injection vulnerabilities, CSP does not directly prevent Cross-Site Request Forgery (CSRF). CSRF attacks involve forging requests that appear legitimate to the server, originating from the victim's browser, rather than injecting malicious scripts or content into the page itself.
Go deeper
Related to this question
Learn chapter
Session Hijacking
Key term
CSRF
Cross-Site Request Forgery is an attack that tricks a user into performing an unwanted action on a web application where they are currently authenticated.
Key term
Cross Site Scripting XSS
Cross Site Scripting (XSS) is a web security vulnerability where an attacker injects malicious scripts into web pages viewed by other users, enabling theft of data or session hijacking.
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.