Problem Statement
Which control best prevents clickjacking on sensitive pages?
Explanation
Clickjacking tricks a user into clicking a hidden frame. Deny framing or allow only trusted parents. Pair this with CSRF defenses on state-changing actions to limit damage.
Code Solution
SolutionRead Only
X-Frame-Options: DENY Content-Security-Policy: frame-ancestors 'none'
