
EC-CouncilEthical Hacking Essentials
Domain 5Objective 3
Session Hijacking Techniques EHE Practice Questions (Page 6)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
34questions here
7free pages
8concepts
Questions 26–30
- 26
A security consultant is testing a web application for session fixation. The application accepts a session ID from a URL parameter and does not validate the origin of the session ID. Which test would best confirm the vulnerability?
Select an answer first - 27
A security team is investigating a series of fraudulent transactions in an online banking application. The users are accessing the application from their personal computers, and the bank uses HTTPS, Secure cookies, and two-factor authentication. The bank suspects a man-in-the-browser attack. Which evidence would most strongly support this suspicion?
Select an answer first - 28
A penetration tester is assessing a web application that generates session IDs using a predictable pattern based on the current timestamp and a small random number. The tester successfully predicts a valid session ID for an authenticated user. Which countermeasure would be most effective in preventing this type of attack?
Select an answer first - 29
A security analyst at a coffee shop chain is investigating a report that customers using the shop's free Wi-Fi had their web sessions taken over. The analyst captures traffic and finds that the web application uses HTTP for login and then redirects to HTTPS for the rest of the session, but the session cookie is not marked Secure. Which combination of factors most directly enabled the session takeover?
Select an answer first - 30
Which of the following is an effective countermeasure to prevent session hijacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.