DeepFrontend
Learning Paths
Practice
System Design & DS
Design Studio
Data Structures Curriculum
Real-World Case Studies
Careers
Job Board
Resume Builder
Blog
Sign in
Search
⌘K
Go Pro
Loading compiler resources...
Web Security Quiz Practice
Active Recall Drill Session
← Exit Session
Question 1 of 1
medium
Web Security
Why does the topic recommend layering a CSRF token even when SameSite=Lax is already set on the session cookie?
A
SameSite=Lax doesn't actually work in any browser
B
SameSite is a browser-enforced behavior with historically inconsistent edge cases and no protection on very old browsers, so a token adds defense-in-depth for high-value actions
C
CSRF tokens are required by law
D
Tokens replace the need for HTTPS
Check Answer