Identifying CSRF from Account Lockout and Password Change

Answer Correct answer: A — Cross-site request forgery is the cause, as the attacker tricked the authenticated browser into submitting an unintended password change request.

A website user is locked out of an account after clicking an email link and visiting a different website. Web server logs show the user’s password was changed, even though the user did not change the password. Which of the following is the most likely cause?

  1. Cross-site request forgery Correct Answer
  2. Directory traversal
  3. ARP poisoning
  4. SQL injection

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to distinguish between attacks based on the mechanism of action: CSRF exploits trusted relationships for state-changing requests, whereas SQL injection targets data integrity via database queries.

This scenario describes a Cross-Site Request Forgery (CSRF) attack where an attacker forces an authenticated user to perform unintended actions. The key indicator is the unauthorized password change triggered by visiting a malicious site while logged into the target service.

Candidates often confuse CSRF with SQL Injection because both compromise security. However, SQL injection requires input manipulation of query parameters, not just visiting a link that triggers browser-side requests.

Community Discussion (3 comments)

shady23 👍 1 Selected: A
A. Cross-site request forgery Cross-site request forgery (CSRF) is the most likely cause in this scenario. CSRF occurs when a user is tricked into performing actions on a website without their knowledge or consent. In this case, the user clicked on an email link, likely leading them to a malicious website that executed a request to change the user's password on the legitimate website where they were logged in. The user's session was exploited to perform unauthorized actions, such as changing the password, without their explicit consent. This type of attack can be prevented by implementing mechanisms like CSRF tokens to validate the origin of requests.
7308365 👍 4
A. Cross-site request forgery (XSRF) is a malicious script hosted on the attacker's site that can exploit a session started on another site in the same browser. Also known as client-side forgery or CSRF The user is locked out of an account only after clicking an email link and visiting a different website indicating that cross-site forgery most likely took place
Hs1208 👍 4 Selected: A
Cross-site request forgery (CSRF) (Option A): CSRF is an attack where a malicious website tricks a user's browser into making an unintended request to another site where the user is authenticated. In this case, clicking the email link and visiting a different website could have initiated a request to change the password on the target website without the user's knowledge

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Cross-Site Request Forgery (CSRF) occurs when a malicious website tricks a user's browser into sending an authenticated request to a trusted site. In this scenario, the user clicks a link on a different website (the attacker's site) while still authenticated on the target web server. The attacker's site likely contains code that automatically submits a form or makes an API call to change the user's password. Since the browser includes valid session cookies with this request, the target server processes it as a legitimate action, resulting in the password change and subsequent lockout.

Why the Other Options Are Wrong

Directory traversal involves manipulating file paths to access restricted files, which does not result in account credential changes. ARP poisoning is a Layer 2 attack used for man-in-the-middle interception, not for directly executing state-changing commands within a web application context. SQL injection involves injecting malicious SQL code into input fields to manipulate the database; it typically requires specific input vectors rather than simply clicking a link to another domain.

Community Comment Notes

The community consensus strongly supports CSRF, noting that the attack exploits the trust a site has in the user's browser. As noted by user 7308365, the key is that the malicious script exploits a session started on another site. User Hs1208 correctly identifies that the visiting of a different website initiated the unintended request without the user's knowledge.

Exam Strategy

When analyzing web attacks, look at the trigger mechanism. If the trigger is 'visiting a site' or 'clicking a link' while authenticated elsewhere, think CSRF. If the trigger is 'inputting text' into a form field, think SQL Injection or XSS.

Frequently Asked Questions

How does CSRF differ from XSS in this scenario?

XSS injects malicious scripts into a trusted site. CSRF uses the trusted site itself to make requests. Here, the user visited a different site that talked back to the target site.

Why isn't this SQL Injection?

SQL Injection requires manipulating database queries through input fields. Clicking a link to another domain cannot execute SQL code against the target database directly.

Related Analysis

← Back to SY0-601 Study Guide