
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 2
Session Fixation WAHS Practice Questions (Page 9)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
9concepts
Questions 41–43
- 41
A web application is being redesigned. The security architect wants to implement secure session management to prevent session fixation. Which set of practices should be included in the design?
Select an answer first - 42
Which technique is used to validate that a session ID belongs to the legitimate user?
Select an answer first - 43
An attacker is planning a session fixation attack against a web application that uses cookies for session management. The application does not accept session IDs from URLs or forms. Which delivery method could the attacker use to set the victim's session ID?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to WAHS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.