Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 4Objective 1

Network-Level Attacks (sniffing, DoS/DDoS, Session Hijacking) ECSS Practice Questions (Page 9)

Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.

51questions here
11free pages
12concepts

Questions 41–45

  1. 41expert · hard

    A penetration tester is performing a DNS spoofing attack on a local network. The tester wants to redirect a victim's traffic to a malicious server for a specific domain, but the victim uses a DNS server that is not vulnerable to cache poisoning. Which technique could the tester use?

    Select an answer first
  2. 42application · medium

    A security analyst is reviewing web application logs and notices that a user's session ID was sent in the URL query string. The analyst is concerned that an attacker could capture this session ID from proxy logs or browser history. Which countermeasure would best prevent session hijacking in this scenario?

    Select an answer first
  3. 43expert · medium

    A web application developer wants to protect against session hijacking. The application uses cookies for session management. The developer is considering implementing HTTP-only cookies, Secure cookies, and a short session timeout. Which combination of these measures is most effective?

    Select an answer first
  4. 44expert · hard

    A security analyst is investigating a session hijacking incident. The attacker was able to take over an authenticated session on a web application. The application uses HTTPS and sets the Secure and HttpOnly flags on session cookies. The analyst suspects the attack occurred via a man-in-the-middle (MITM) attack. Which additional countermeasure would be most effective?

    Select an answer first
  5. 45expert · hard

    A company is experiencing a DDoS attack that is saturating their internet link. The attack consists of large ICMP echo requests from many spoofed IP addresses. The company wants to mitigate the attack without affecting legitimate ICMP traffic (e.g., ping for troubleshooting). Which mitigation is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.