Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam 312-50v10 topic 1 question 261 discussion

Actual exam question from ECCouncil's 312-50v10
Question #: 261
Topic #: 1
[All 312-50v10 Questions]

While performing online banking using a Web browser, a user receives an email that contains a link to an interesting Web site. When the user clicks on the link, another Web browser session starts and displays a video of cats playing a piano. The next business day, the user receives what looks like an email from his bank, indicating that his bank account has been accessed from a foreign country. The email asks the user to call his bank and verify the authorization of a funds transfer that took place. What Web browser-based security vulnerability was exploited to compromise the user?

  • A. Clickjacking
  • B. Cross-Site Scripting
  • C. Cross-Site Request Forgery
  • D. Web form input validation
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Xipher
3 years, 3 months ago
Is definitely CRSF cos if you get the question well it means an action was taken which inturn wasnt taken by the user but the attacker. That makes it CRSF
upvoted 2 times
...
gizicudu
3 years, 5 months ago
@AnAnan Maybe using CSRF he just did password reset which he then used to login and do the funds? There's no information about XSS vulnerable page so I'd still go for CSRF
upvoted 2 times
...
AnAnon
3 years, 6 months ago
The best answer should be B (XSS) because : - you need a script to open a new window and to retreive at the same time some informations - in a CSRF, the browser of the user will make the request, so there will not be an access from another country
upvoted 2 times
gizicudu
3 years, 5 months ago
Maybe using CSRF he just did password reset which he then used to login and do the funds? There's no information about XSS vulnerable page so I'd still go for CSRF
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...