Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 5Objective 3

Session Hijacking Techniques EHE Practice Questions (Page 3)

Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.

34questions here
7free pages
8concepts

Questions 11–15

  1. 11application · medium

    An attacker sends a victim a link that sets the victim's session ID to a known value. After the victim logs in, the attacker uses that known session ID to access the victim's account. Which step in the session hijacking process does this attack primarily exploit?

    Select an answer first
  2. 12foundation · easy

    What is the primary reason that using the HttpOnly flag on session cookies helps prevent XSS-based session hijacking?

    Select an answer first
  3. 13foundation · easy

    What is the typical first step in a session hijacking attack?

    Select an answer first
  4. 14expert · hard · select all that apply

    A security architect is designing a comprehensive session management strategy for a web application. The application must protect against session fixation, side-jacking, and XSS-based cookie theft. Which of the following controls should be implemented? Select all that apply.

    Select an answer first
  5. 15application · medium

    A bank customer's browser has a malicious browser extension installed. When the customer logs into online banking, the extension silently modifies the page's JavaScript to change the destination account number in a fund transfer request. The transaction appears to succeed, but the money goes to the attacker's account. Which attack best describes this scenario?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.