CEH Session Hijacking Practice Question
Which TWO of the following are examples of session hijacking attacks? (Select 2)
⚠ Common exam trap
It's easy for candidates to confuse network-level attacks (like ARP poisoning or DNS spoofing) with session hijacking, but the CEH exam specifically defines session hijacking as the takeover of an authenticated TCP or application-layer session, which requires either stealing a session token (cookie theft) or predicting TCP sequence numbers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cookie theft
Cookie theft (B) is a session hijacking attack because an attacker who steals a valid session cookie (e.g., via XSS or sniffing an unencrypted HTTP session) can replay it to impersonate the victim and take over the authenticated session. TCP sequence prediction (D) is also session hijacking: by predicting the ISN (initial sequence number) of a TCP connection, an attacker can inject spoofed packets and desynchronize or take over an established session. DNS spoofing (A), MAC flooding (C), and ARP poisoning (E) are supporting or denial-of-service attacks — DNS spoofing redirects name resolution, MAC flooding overflows a switch's CAM table, and ARP poisoning enables MITM traffic interception — but none of them by themselves constitute session hijacking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS spoofing
Why it's wrong here
DNS spoofing redirects name resolution to a fraudulent address, so a client connects to an attacker's server rather than an existing session being taken over. It tempts because it is a redirection attack, but session hijacking requires capturing and reusing a valid session identifier.
- ✓
Cookie theft
Why this is correct
Cookie theft hijacks an established session by stealing the session identifier, letting the attacker replay it to impersonate the victim without re-authenticating. This directly satisfies the session-hijacking criterion, since the attacker takes over an already-authenticated session rather than cracking credentials.
- ✗
MAC flooding
Why it's wrong here
MAC flooding exhausts a switch's CAM table, forcing frames to flood, which enables sniffing rather than hijacking an established session. It tempts because it is a layer-two attack that can precede session theft, but it is a traffic-disclosure technique, not session hijacking itself.
- ✓
TCP sequence prediction
Why this is correct
TCP sequence prediction hijacks a session by forecasting the next sequence and acknowledgement numbers, allowing injected packets to be accepted as legitimate. This satisfies the session-hijacking criterion because the attacker assumes an existing connection rather than authenticating independently.
- ✗
ARP poisoning
Why it's wrong here
ARP poisoning manipulates the ARP cache to intercept traffic, enabling session hijacking rather than being one itself; it is a precursor technique. It is tempting because it is a common attack vector, but it belongs to man-in-the-middle positioning, not the hijacking of an already-established session token.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Session Hijacking
Key term
Cross Site Scripting XSS
Cross Site Scripting (XSS) is a web security vulnerability where an attacker injects malicious scripts into web pages viewed by other users, enabling theft of data or session hijacking.
Key term
Session Hijacking
Session hijacking is an attack where a cybercriminal steals or takes over a user's active session with a web application, allowing the attacker to pretend to be that user without needing their password.
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.