
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 2
Session Fixation WAHS Practice Questions (Page 7)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
9concepts
Questions 31–35
- 31
Which of the following is a common method an attacker uses to deliver a fixed session ID to a victim?
Select an answer first - 32
Which automated testing approach can help identify session fixation vulnerabilities?
Select an answer first - 33
A security engineer is implementing session management for a high-security web application. The application must support users who log in from multiple devices and also allow single sign-on (SSO) via an external identity provider. The engineer wants to prevent session fixation while minimizing disruption to legitimate users. Which approach is BEST?
Select an answer first - 34
A security tester is using an automated scanner to check for session fixation. The scanner reports that the application does not regenerate session IDs after login. Which additional manual test should the tester perform to confirm the vulnerability?
Select an answer first - 35
A developer is implementing a login function. The application currently uses a cookie-based session. Which code change would BEST prevent session fixation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.