Q13Processes
A company recently finished an internal audit and found a CSRF vulnerability in 20 of its hosted applications. Based on the audit, which patching recommendation should an engineer make?
← → navigate · a answer
Community votes
Discussion · 4
D 2
Selected Answer: D
Cross-Site Request Forgery (CSRF) is a type of attack that happens when a malicious web site, email, blog, instant message, or program causes a user's web browser to perform an unwanted action on a trusted site when the user is authenticated. A CSRF attack works because browser requests automatically include all cookies, including session cookies. Therefore, if the user is authenticated to the site, the site cannot distinguish between legitimate authorized requests and forged authenticated requests.
https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html
D fits here, any concerns?
2
D. Fix applications based on the risk scores.
To prioritize the patching process, the engineer should prioritize applications based on their risk scores. Risk scoring allows for a systematic evaluation of the level of risk associated with the applications and assists in determining the order of priority for addressing the vulnerabilities. This ensures that the most critical applications are patched first, thereby mitigating the risk of a successful attack.
Identifying the business applications running on the assets (Option A) is an important step, but it does not directly address the issue of patching the CSRF vulnerability. Updating software to patch third-party software (Option B) is also important, but may not be the most critical step at this time. Validating CSRF by executing exploits In order to prioritize the patching process, the engineer should prioritize applications based on their risk scores. within Metasploit (Option C) is not necessary as the vulnerability has already been identified.
D 1
Selected Answer: D
When handling a CSRF vulnerability found across multiple applications, the recommended approach is to prioritize patching based on the risk scores tied to each application. This makes sure the most critical vulnerabilities that present the greatest risk to the organization are addressed first. It is a strategic approach that lines up remediation efforts with the possible impact of the vulnerabilities4.
D 1
Selected Answer: D
ChatGPT: The best approach is to fix applications according to their risk scores. That makes sure the most critical vulnerabilities, which could lead to serious security breaches, are handled first, lowering the overall risk to the organization.