
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 2
Session Fixation WAHS Practice Questions (Page 5)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
9concepts
Questions 21–25
- 21
A security team is hardening a web application that has experienced session fixation attacks. They plan to regenerate the session ID after login, but they also want to add a defense-in-depth measure that makes it harder for an attacker to use a fixed session ID even if regeneration is bypassed. Which additional control would be MOST effective?
Select an answer first - 22
What is the core characteristic of a session fixation attack?
Select an answer first - 23
A web application is being redesigned for better security. The team wants to implement secure session management from scratch. Which combination of controls should be included to specifically prevent session fixation?
Select an answer first - 24
When should a web application regenerate the session ID to effectively mitigate session fixation?
Select an answer first - 25
After the victim authenticates in a session fixation attack, what does the attacker do to gain access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.