Courseiva
Secure Software ImplementationhardMultiple ChoiceObjective-mapped

CSSLP Secure Software Implementation Practice Question

In a Java Spring Boot application, which configuration prevents Cross-Site Request Forgery (CSRF) for state-changing HTTP requests?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure the HttpSecurity object to require CSRF tokens

Spring Security enables CSRF protection by default, which validates tokens for non-GET requests; disabling it (csrf().disable()) is the primary cause of vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Set the Content-Type header to application/json

    Why it's wrong here

    Changing the header does not prevent CSRF attacks.

  • Use a stateless session strategy with no tokens

    Why it's wrong here

    Stateless APIs still require CSRF protection if they use cookies for authentication.

  • Configure the HttpSecurity object to require CSRF tokens

    Why this is correct

    Validating CSRF tokens ensures the request originated from the trusted UI.

  • Enable csrf().disable() in the SecurityFilterChain

    Why it's wrong here

    This explicitly turns off the protection.

About these practice questions

One of 198 original CSSLP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official (ISC)² exam blueprint

This CSSLP practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CSSLP exam.