Courseiva

CEH Session Hijacking Practice Question

Which TWO of the following are examples of session hijacking attacks? (Select 2)

⚠ Common exam trap

It's easy for candidates to confuse network-level attacks (like ARP poisoning or DNS spoofing) with session hijacking, but the CEH exam specifically defines session hijacking as the takeover of an authenticated TCP or application-layer session, which requires either stealing a session token (cookie theft) or predicting TCP sequence numbers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cookie theft

Cookie theft (B) is a session hijacking attack because an attacker who steals a valid session cookie (e.g., via XSS or sniffing an unencrypted HTTP session) can replay it to impersonate the victim and take over the authenticated session. TCP sequence prediction (D) is also session hijacking: by predicting the ISN (initial sequence number) of a TCP connection, an attacker can inject spoofed packets and desynchronize or take over an established session. DNS spoofing (A), MAC flooding (C), and ARP poisoning (E) are supporting or denial-of-service attacks — DNS spoofing redirects name resolution, MAC flooding overflows a switch's CAM table, and ARP poisoning enables MITM traffic interception — but none of them by themselves constitute session hijacking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS spoofing

    Why it's wrong here

    DNS spoofing redirects name resolution to a fraudulent address, so a client connects to an attacker's server rather than an existing session being taken over. It tempts because it is a redirection attack, but session hijacking requires capturing and reusing a valid session identifier.

  • ✓

    Cookie theft

    Why this is correct

    Cookie theft hijacks an established session by stealing the session identifier, letting the attacker replay it to impersonate the victim without re-authenticating. This directly satisfies the session-hijacking criterion, since the attacker takes over an already-authenticated session rather than cracking credentials.

  • ✗

    MAC flooding

    Why it's wrong here

    MAC flooding exhausts a switch's CAM table, forcing frames to flood, which enables sniffing rather than hijacking an established session. It tempts because it is a layer-two attack that can precede session theft, but it is a traffic-disclosure technique, not session hijacking itself.

  • ✓

    TCP sequence prediction

    Why this is correct

    TCP sequence prediction hijacks a session by forecasting the next sequence and acknowledgement numbers, allowing injected packets to be accepted as legitimate. This satisfies the session-hijacking criterion because the attacker assumes an existing connection rather than authenticating independently.

  • ✗

    ARP poisoning

    Why it's wrong here

    ARP poisoning manipulates the ARP cache to intercept traffic, enabling session hijacking rather than being one itself; it is a precursor technique. It is tempting because it is a common attack vector, but it belongs to man-in-the-middle positioning, not the hijacking of an already-established session token.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.