A GIAC administrator has configured their company's web server to send an X-Frame-Options header in every request to an HTTP page. The admin has configured the option to use the values DENY, SAMEORIGIN, or ALLOW-FROM. What attack is the administrator addressing with the techniques described above? 1) SQL injection 2) Cross-Site request forgery 3) Cross-Site scripting 4) Directory traversal 5) Clickjacking