Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 4Objective 4

Session Hijacking CEH Practice Questions (Page 7)

Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts

Questions 31–35

  1. 31expert · hard

    A network security engineer is designing defenses against TCP session hijacking. The organization has a mix of legacy systems that do not support encryption and modern systems that do. Which control is the most effective at preventing off-path TCP session hijacking?

    Select an answer first
  2. 32expert · hard

    A SOC analyst is reviewing logs and notices that a user's session ID was used from two different geographic locations within 5 minutes. The user is a remote employee who travels frequently. The analyst must decide whether this is a hijacking attempt or a false positive. Which additional data point would most help the analyst make this determination?

    Select an answer first
  3. 33expert · hard

    A penetration tester is conducting a session hijacking test against a web application that uses a session cookie. The tester has successfully captured a valid session cookie using a network sniffer. The tester wants to use the cookie to access the application as the victim. Which tool would be most appropriate to replay the cookie?

    Select an answer first
  4. 34application · medium

    A penetration tester is attempting to hijack a session by predicting the session ID. The application uses a session ID that is generated using a linear congruential generator (LCG). Which attack is the tester most likely to use?

    Select an answer first
  5. 35foundation · easy

    Why is session hijacking considered a serious threat to web application security?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.