
EC-CouncilCertified Security Specialist
Domain 4Objective 1
Network-Level Attacks (sniffing, DoS/DDoS, Session Hijacking) ECSS Practice Questions (Page 8)
Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
12concepts
Questions 36–40
- 36
A penetration tester is attempting to hijack a TCP session between a client and a server. The tester can observe the network traffic and wants to inject malicious data into the session. The tester has successfully predicted the next sequence number. Which action should the tester take to complete the hijack?
Select an answer first - 37
A network administrator is troubleshooting intermittent connectivity issues on a switch. The switch logs show that the CAM table is frequently full, and the switch is broadcasting frames to all ports. Which attack is likely occurring?
Select an answer first - 38
What is a session token used for in web applications?
Select an answer first - 39
A penetration tester is hired to assess a company's internal network. The tester connects a laptop to a switch port and needs to capture traffic between two other hosts on the same VLAN. The switch does not support port mirroring. Which technique should the tester use to redirect the target's traffic through the tester's machine so it can be captured?
Select an answer first - 40
What is the primary difference between active and passive session hijacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.