Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 5Objective 3

Session Hijacking Techniques EHE Practice Questions (Page 5)

Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.

34questions here
7free pages
8concepts

Questions 21–25

  1. 21foundation · easy

    How can an attacker predict or guess a session ID to hijack a session?

    Select an answer first
  2. 22foundation · easy

    What is a man-in-the-browser (MitB) attack?

    Select an answer first
  3. 23foundation · easy

    Which of the following best describes the impact of a successful session hijacking attack on a web application?

    Select an answer first
  4. 24application · medium

    A penetration tester is assessing a web application that displays user-supplied comments without sanitization. The tester wants to demonstrate how an attacker could steal a victim's session cookie. Which payload would achieve this if the victim's browser executes it?

    Select an answer first
  5. 25application · medium

    An attacker sends a victim a link that sets the victim's session ID to a value the attacker already knows. After the victim logs in, the attacker uses that known session ID to access the victim's account. Which defense would most effectively block this attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.