CISSP Software Development Security Practice Question
A security analyst is reviewing a web application that handles financial transactions. Which TWO of the following are effective controls against Cross-Site Request Forgery (CSRF)?
⚠ Common exam trap
CISSP often tests the misconception that HTTPS or input validation prevents CSRF — candidates must recognize that CSRF is an origin/authorization problem, not a confidentiality or injection problem, so only token-based and SameSite controls address it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Setting cookies with the SameSite attribute to Strict
Option A is correct because setting cookies with the SameSite attribute to Strict prevents the browser from sending the session cookie on cross-site requests, which blocks the CSRF attack vector since the attacker's forged request lacks the victim's authentication cookie. Option B is correct because anti-CSRF tokens (synchronizer tokens) are unique, unpredictable values embedded in forms and validated server-side, ensuring that a request originates from the legitimate application page rather than a forged cross-site request. Option C is not correct because HTTPS only encrypts data in transit and does not prevent a browser from automatically attaching credentials to a forged request. Option D is not correct because strong password policies address credential guessing and brute-force attacks, not the abuse of an already-authenticated session. Option E is not correct because input validation mitigates injection flaws like XSS or SQLi, but does not stop a forged request that contains valid, expected input.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Setting cookies with the SameSite attribute to Strict
Why this is correct
The SameSite=Strict attribute on cookies ensures that the browser will only send the cookie with requests originating from the same site as the cookie's domain. This effectively prevents a malicious third-party site from tricking a user's browser into sending authenticated requests to the legitimate application, thereby mitigating Cross-Site Request Forgery (CSRF) attacks. It provides a robust defense by restricting cookie transmission to first-party contexts only.
- ✓
Using anti-CSRF tokens in forms
Why this is correct
Anti-CSRF tokens are unique, unpredictable, and session-specific values embedded within web forms or request parameters. The server generates these tokens and associates them with the user's session, then validates their presence and correctness upon form submission. If a request lacks a valid token, or if the token does not match the server's expectation, the request is rejected, effectively preventing an attacker from forging legitimate requests.
- ✗
Using HTTPS for all pages
Why it's wrong here
While using HTTPS for all pages is crucial for protecting data confidentiality and integrity during transit, it does not directly prevent Cross-Site Request Forgery (CSRF) attacks. HTTPS encrypts the communication channel between the client and server, preventing eavesdropping and tampering. However, CSRF exploits the browser's trust in the user's authenticated session, not the security of the transport layer itself, allowing a forged request to be sent over an encrypted connection.
- ✗
Enforcing strong password policies
Why it's wrong here
Enforcing strong password policies is a fundamental security practice that helps protect user accounts from brute-force attacks, dictionary attacks, and credential stuffing. However, strong passwords do not offer any protection against Cross-Site Request Forgery (CSRF). CSRF attacks exploit a user's active, authenticated session by tricking their browser into sending a request, rather than attempting to guess or compromise their login credentials.
- ✗
Implementing input validation on all user inputs
Why it's wrong here
Implementing robust input validation on all user inputs is essential for preventing a wide range of vulnerabilities, such as SQL injection, Cross-Site Scripting (XSS), and command injection, by ensuring that data conforms to expected formats and types. However, input validation does not prevent Cross-Site Request Forgery (CSRF). CSRF attacks bypass the need for malicious input by leveraging the user's browser to send legitimate-looking requests, regardless of the input's validity.
Visual reference
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.