
EC-CouncilCertified Ethical Hacker
Domain 4Objective 4
Session Hijacking CEH Practice Questions (Page 8)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 36–40
- 36
What is a common mitigation technique to limit the impact of a session hijacking attack?
Select an answer first - 37
A network administrator notices unusual TCP traffic from an internal host that is sending packets with sequence numbers that do not match the expected window. The administrator suspects an active session hijacking attempt. Which technique is the attacker most likely using, and what immediate step should the administrator take to confirm?
Select an answer first - 38
A security team is implementing detection for session hijacking. They want to minimize false positives while detecting anomalies. Which approach is the most effective?
Select an answer first - 39
A web developer is hardening a session management system. The application currently uses a session cookie that is accessible to JavaScript and is transmitted over HTTP. Which two changes should the developer make to reduce the risk of session hijacking?
Select an answer first - 40
What is a recommended practice for session management to prevent session hijacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.