
EC-CouncilCertified Ethical Hacker
Domain 4Objective 4
Session Hijacking CEH Practice Questions (Page 6)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 26–30
- 26
A security architect is designing a defense-in-depth strategy for a web application that handles sensitive user data. The architect wants to implement multiple layers of protection against session hijacking. Which combination of controls is most effective?
Select an answer first - 27
A web application administrator is configuring session management to prevent session hijacking. The application is hosted on HTTPS and uses a session cookie. Which configuration provides the strongest protection against session theft?
Select an answer first - 28
What is the primary purpose of a session ID in a web application?
Select an answer first - 29
A security operations center (SOC) analyst is monitoring a web application and notices that a user's session ID is being used from two different IP addresses within a short time frame. The analyst suspects session hijacking. Which action should the analyst take first?
Select an answer first - 30
How does cross-site scripting (XSS) enable session hijacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.