Identifying CSRF from Account Lockout and Password Change
A website user is locked out of an account after clicking an email link and visiting a different website. Web server logs show the user’s password was changed, even though the user did not change the password. Which of the following is the most likely cause?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to distinguish between attacks based on the mechanism of action: CSRF exploits trusted relationships for state-changing requests, whereas SQL injection targets data integrity via database queries.
This scenario describes a Cross-Site Request Forgery (CSRF) attack where an attacker forces an authenticated user to perform unintended actions. The key indicator is the unauthorized password change triggered by visiting a malicious site while logged into the target service.
Candidates often confuse CSRF with SQL Injection because both compromise security. However, SQL injection requires input manipulation of query parameters, not just visiting a link that triggers browser-side requests.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Cross-Site Request Forgery (CSRF) occurs when a malicious website tricks a user's browser into sending an authenticated request to a trusted site. In this scenario, the user clicks a link on a different website (the attacker's site) while still authenticated on the target web server. The attacker's site likely contains code that automatically submits a form or makes an API call to change the user's password. Since the browser includes valid session cookies with this request, the target server processes it as a legitimate action, resulting in the password change and subsequent lockout.Why the Other Options Are Wrong
Directory traversal involves manipulating file paths to access restricted files, which does not result in account credential changes. ARP poisoning is a Layer 2 attack used for man-in-the-middle interception, not for directly executing state-changing commands within a web application context. SQL injection involves injecting malicious SQL code into input fields to manipulate the database; it typically requires specific input vectors rather than simply clicking a link to another domain.Community Comment Notes
The community consensus strongly supports CSRF, noting that the attack exploits the trust a site has in the user's browser. As noted by user 7308365, the key is that the malicious script exploits a session started on another site. User Hs1208 correctly identifies that the visiting of a different website initiated the unintended request without the user's knowledge.Exam Strategy
When analyzing web attacks, look at the trigger mechanism. If the trigger is 'visiting a site' or 'clicking a link' while authenticated elsewhere, think CSRF. If the trigger is 'inputting text' into a form field, think SQL Injection or XSS.
Frequently Asked Questions
How does CSRF differ from XSS in this scenario?
XSS injects malicious scripts into a trusted site. CSRF uses the trusted site itself to make requests. Here, the user visited a different site that talked back to the target site.
Why isn't this SQL Injection?
SQL Injection requires manipulating database queries through input fields. Clicking a link to another domain cannot execute SQL code against the target database directly.