
EC-CouncilCertified Ethical Hacker
Domain 4Objective 4
Session Hijacking CEH Practice Questions (Page 9)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 41–45
- 41
Which tool is commonly used to capture network traffic and extract session cookies from unencrypted HTTP sessions?
Select an answer first - 42
A security tester is evaluating a web application that allows users to log in. The tester notices that the application does not change the session ID after login. Which attack is this vulnerability most likely to enable, and what is the best mitigation?
Select an answer first - 43
Which attack technique involves an attacker predicting or guessing a valid session ID without intercepting it?
Select an answer first - 44
A security analyst is investigating a potential TCP session hijacking incident. The analyst has a packet capture of the suspicious traffic. The capture shows that the attacker's packets have sequence numbers that are within the expected window, but the ACK numbers are incorrect. The analyst also notices that the attacker is not receiving any responses from the server. Which condition is most likely causing the attacker's lack of success?
Select an answer first - 45
A security operations center (SOC) analyst is monitoring a web application for session hijacking. The analyst notices that a user's session ID changes unexpectedly while the user is actively using the application. Which action should the analyst take first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.