
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 2
Session Fixation WAHS Practice Questions (Page 2)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
9concepts
Questions 6–10
- 6
A security audit of a web application reveals that it accepts session IDs from query strings and does not regenerate session IDs after login. Which two changes should be prioritized to fix the session fixation vulnerability?
Select an answer first - 7
Why should a web application reject session IDs that are not recognized or are invalid?
Select an answer first - 8
In a session fixation attack, how does the attacker typically set the victim's session identifier to a known value?
Select an answer first - 9
How can binding a session ID to a user attribute, such as the IP address, help mitigate session fixation?
Select an answer first - 10
A security analyst is explaining the difference between session fixation and session hijacking to a colleague. Which statement is accurate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.