Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

A penetration tester is performing a session hijacking attack. After capturing packets, the tester successfully predicts the TCP sequence numbers and injects packets to take over the session. Which type of attack is this?

⚠ Common exam trap

In EC-CEH, the trap is distinguishing TCP session hijacking (Layer 4, sequence number prediction) from application-layer session hijacking (e.g., session token theft or cookie theft). Candidates often confuse the mechanism of predicting sequence numbers with stealing session identifiers, leading them to choose Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP session hijacking

TCP session hijacking involves an attacker predicting or spoofing TCP sequence numbers to inject malicious packets into an established TCP connection, effectively taking over the session without the need for authentication. This attack exploits the lack of built-in authentication in TCP's three-way handshake and sequence number generation, allowing the attacker to impersonate one of the communicating parties.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MAC flooding

    Why it's wrong here

    MAC flooding overwhelms a switch's CAM table, causing it to flood frames so a sniffer can capture traffic. It does not predict TCP sequence numbers or inject packets. It is tempting because it enables eavesdropping, but the described injection and sequence-number prediction indicate TCP session hijacking instead.

  • ✗

    Cookie theft

    Why it's wrong here

    Cookie theft involves stealing a session cookie to impersonate a user at the application layer; it does not involve predicting TCP sequence numbers or injecting packets. It is tempting because both achieve session takeover, but the described mechanism is transport-layer sequence-number prediction, not cookie replay.

  • ✓

    TCP session hijacking

    Why this is correct

    Predicting TCP sequence numbers lets the tester forge packets that the server accepts as belonging to the victim's established connection, bypassing authentication entirely. This is TCP session hijacking specifically, since the attacker takes over an existing session rather than guessing credentials or intercepting a new handshake.

  • ✗

    ARP poisoning

    Why it's wrong here

    ARP poisoning redirects traffic by forging ARP replies to associate an attacker's MAC with a victim's IP, enabling interception. It does not predict TCP sequence numbers or inject packets. It is tempting because it facilitates man-in-the-middle capture, but the takeover here relies on sequence-number prediction, not ARP manipulation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.