
EC-CouncilEthical Hacking Essentials
Domain 5Objective 3
Session Hijacking Techniques EHE Practice Questions (Page 2)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
34questions here
7free pages
8concepts
Questions 6–10
- 6
Which of the following session ID characteristics makes it most vulnerable to prediction attacks?
Select an answer first - 7
A penetration tester is attempting to hijack a session in a web application. The tester has identified a stored XSS vulnerability and also notices that the application uses HTTP for some pages. Which attack sequence would be most effective?
Select an answer first - 8
A security analyst is investigating a session hijacking incident. The attacker first sniffed the victim's session cookie over an unencrypted Wi-Fi network, then used that cookie to impersonate the victim. Which sequence best describes the steps the attacker took?
Select an answer first - 9
A developer is writing a web application and wants to mitigate session hijacking via XSS. The application already uses HTTPS and sets the HttpOnly attribute on the session cookie. Which additional measure would most effectively prevent an attacker from using XSS to steal the session cookie?
Select an answer first - 10
A web application has a stored XSS vulnerability in a comment field. The application uses HTTPS and sets the HttpOnly attribute on the session cookie. An attacker wants to hijack a victim's session. Which technique would be most effective despite the HttpOnly attribute?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.