ALL PASS, NO FAIL!

CEH v13 Module 11: Session Hijacking — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 11 of 20

Stealing active sessions: session sniffing, session fixation, cookies and tokens, and defenses like HTTPS and re-authentication. Exam focus: sequence prediction, session fixation, and cookie theft are the core trio. Know why HTTPS alone does not stop fixation attacks and which token characteristics — entropy, rotation, binding — actually defeat them.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: Session hijacking is:

Answer: C — Most authentication happens once at session start — seize the session ID and the server trusts you.

Question 2: The classic phases of TCP session hijacking are:

Answer: C — 1) Track with a sniffer to learn sequence numbers, 2) desync (e.g., RST or null data) so the victim's state drifts, 3) inject attacker packets that the server accepts.

Question 3: Passive session hijacking differs from active hijacking because it:

Answer: C — Active hijacking takes over the live conversation — desync, spoof, inject — and must win a race against the victim's sequence numbers.

Question 4: In session fixation, the attacker:

Answer: B — If the app doesn't regenerate the ID at login, the attacker's pre-known ID becomes the authenticated session — fix: rotate session ID on authentication.

Question 5: The CRIME attack exploits:

Answer: C — Compression shrinks repeated secrets (cookies) more than random bytes — measuring compressed sizes reveals them. Mitigation: disable TLS compression.

Question 6: Cross-Site Request Forgery (CSRF) works because:

Answer: B — Prevention: per-session anti-CSRF tokens, SameSite cookie attributes, and re-authentication for sensitive actions.

Question 7: A Man-in-the-Browser attack typically:

Answer: A — The trojan registers for targeted sites and rewrites DOM field values on submission — the server receives altered data while the user sees normal.

Question 8: RST injection (RST hijacking) is used to:

Answer: C — A single well-formed RST (correct IP/ports/sequence) tears the connection down — used to desynchronize victims before takeover.

Question 9: In blind session hijacking, the attacker:

Answer: C — Without seeing replies, the attacker fires candidate packets hoping the predicted sequence number is accepted — low success rate but functional.

Question 10: Which cookie-flag combination best protects against client-side session theft?

Answer: D — Secure forces HTTPS, HttpOnly blocks document.cookie access via XSS, and SameSite restricts cross-site cookie sending.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Session Hijacking practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 11 (Session Hijacking). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 11 (Session Hijacking) cover?

Stealing active sessions: session sniffing, session fixation, cookies and tokens, and defenses like HTTPS and re-authentication. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 11 flashcards at https://cehstudy.com/ceh-v13/module-11/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Session Hijacking quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Session Hijacking flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 11 (Session Hijacking). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 11 page at https://cehstudy.com/ceh-v13/module-11/. No account or sign-up required.