
EC-CouncilEthical Hacking Essentials
Domain 5Objective 3
Session Hijacking Techniques EHE Practice Questions (Page 4)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
34questions here
7free pages
8concepts
Questions 16–20
- 16
A security analyst notices that a public Wi-Fi network in a coffee shop is capturing traffic. A user logs into a web application that uses only HTTP for the session cookie, and the analyst later sees the cookie value in the captured traffic. Which combination of controls would best prevent this type of session theft?
Select an answer first - 17
After an attacker has obtained a valid session ID, what is the next step in a session hijacking attack?
Select an answer first - 18
A developer at a small e-commerce company discovers that the web application reflects user input in error messages without proper sanitization. An attacker exploits this to inject a script that sends the current session cookie to an external server. Which countermeasure would most directly prevent this specific attack from succeeding?
Select an answer first - 19
A company's web application is accessed over a corporate network. The security team wants to prevent session side-jacking. Which configuration change would be most effective?
Select an answer first - 20
How can cross-site scripting (XSS) be used to steal session cookies?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.