
EC-CouncilCertified Ethical Hacker
Domain 4Objective 4
Session Hijacking CEH Practice Questions (Page 2)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 6–10
- 6
A web developer is implementing a session management system for a banking application. The developer wants to ensure that a stolen session cookie cannot be used from a different device or browser. Which approach is most effective?
Select an answer first - 7
What is the primary goal of a session hijacking attack?
Select an answer first - 8
A security analyst is investigating a series of account takeovers on a corporate web application. The application uses a session token that is a sequential integer, and the analyst notices that the token is included as a query parameter in every URL. Which combination of weaknesses is the most likely root cause of the account takeovers?
Select an answer first - 9
A security team is implementing session management for a high-security application. They have the following requirements: (1) session IDs must be unpredictable, (2) session IDs must be protected from network sniffing, (3) session IDs must be protected from XSS, and (4) the application must be able to detect session hijacking. Which combination of controls best meets all requirements?
Select an answer first - 10
A penetration tester is attempting to steal a session ID from a user of a web application. The application uses a session cookie that is not marked HttpOnly. Which attack vector is the most direct?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.