
EC-CouncilCertified Ethical Hacker
Domain 4Objective 4
Session Hijacking CEH Practice Questions (Page 4)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 16–20
- 16
A penetration tester is performing a session hijacking test on a web application. The tester has access to the same network as the victim and wants to capture the victim's session cookie. Which tool is the most appropriate for this task?
Select an answer first - 17
What is IP spoofing in the context of TCP session hijacking?
Select an answer first - 18
Which of the following is a common method used to steal a session ID?
Select an answer first - 19
A web application has a stored cross-site scripting (XSS) vulnerability. An attacker exploits it to steal session cookies. Which defense would have prevented the attacker from using the stolen cookie?
Select an answer first - 20
A security architect is designing a defense-in-depth strategy against session hijacking. The organization has a legacy application that cannot be modified to use secure cookies. Which additional control is the most effective in mitigating session hijacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.