Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 4Objective 1

Network-Level Attacks (sniffing, DoS/DDoS, Session Hijacking) ECSS Practice Questions (Page 2)

Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.

51questions here
11free pages
12concepts

Questions 6–10

  1. 6application · medium

    A web application currently uses HTTP and sets session cookies without the Secure or HttpOnly flags. The development team wants to reduce the risk of session hijacking. Which combination of changes is most effective?

    Select an answer first
  2. 7foundation · easy

    Which of the following is a widely used open-source network sniffing tool that provides a graphical interface for packet capture and analysis?

    Select an answer first
  3. 8foundation · easy

    What is session fixation?

    Select an answer first
  4. 9application · medium

    A user reports that after logging into a banking website on a public Wi-Fi network, an attacker is able to access the user's account without knowing the password. The attacker likely stole the session cookie. Which countermeasure would be most effective to prevent this?

    Select an answer first
  5. 10foundation · easy

    How can cross-site scripting (XSS) be used to perform session hijacking?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.