
EC-CouncilEthical Hacking Essentials
Domain 5Objective 3
Session Hijacking Techniques EHE Practice Questions (Page 7)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
34questions here
7free pages
8concepts
Questions 31–34
- 31
A bank's security team notices that some customers are seeing unauthorized transactions even though they are using HTTPS and their session cookies are Secure and HttpOnly. The bank suspects a man-in-the-browser attack. Which characteristic is most consistent with a man-in-the-browser attack?
Select an answer first - 32
How does a man-in-the-browser attack contribute to session hijacking?
Select an answer first - 33
What is session hijacking in the context of web security?
Select an answer first - 34
A security auditor is reviewing a web application that generates session IDs using a linear congruential generator with a known seed. The auditor determines that an attacker can predict future session IDs. Which countermeasure would be most effective?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to EHE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.