โ† All Certified Ethical Hacker Flashcard Decks

Session Hijacking and Evading IDS Firewalls Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Session Hijacking and Evading IDS Firewalls flashcards as text
  1. Which IDS evasion technique involves breaking a single exploit into multiple small packets that individually appear harmless?

    Answer: Session Splicing

    Session splicing fragments an attack payload across multiple TCP segments so that the IDS does not reconstruct the full attack signature.

  2. What is the purpose of using Unicode or hex encoding in IDS evasion?

    Answer: To obscure attack strings so signature-based IDS does not detect them

    Encoding attack strings in Unicode or hex can bypass signature-based IDS that only match ASCII patterns, while the target server decodes and executes the payload normally.

  3. Which firewall evasion technique uses a series of intermediate hosts to hide the true source of an attack?

    Answer: Proxy Chaining

    Proxy chaining routes attack traffic through multiple proxy servers, masking the original source IP and making attribution difficult.

  4. What does a stateful firewall track that a stateless (packet-filtering) firewall does not?

    Answer: The state of active network connections

    A stateful firewall maintains a connection state table and tracks the full context of active sessions, allowing it to detect out-of-state packets that stateless firewalls miss.

  5. Which technique involves manipulating the TTL field of packets to confuse IDS reassembly while the target host still receives the attack?

    Answer: TTL Manipulation

    TTL manipulation sets different TTL values so that some decoy packets expire before reaching the IDS but the actual attack payload reaches the target.

  6. What type of IDS evasion injects extra packets into a stream that the IDS accepts but the target host rejects, causing the IDS to build a different view of the session?

    Answer: Insertion Attack

    An insertion attack sends packets with invalid checksums or TTLs that the IDS accepts but the end host drops, causing the IDS to reconstruct a different data stream.