โ† All Certified Ethical Hacker Flashcard Decks

Session Hijacking and Evading IDS Firewalls Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Session Hijacking and Evading IDS Firewalls flashcards as text
  1. Which type of IDS analyzes network traffic patterns against a learned baseline to detect anomalies?

    Answer: Anomaly-Based IDS

    Anomaly-based IDS establishes a baseline of normal behavior and triggers alerts when traffic deviates significantly from that baseline.

  2. What is 'covert channel' communication in the context of firewall evasion?

    Answer: Transmitting data through protocols not intended for data transfer

    Covert channels exploit non-standard use of protocols (e.g., hiding data in ICMP ping payloads or DNS queries) to bypass firewalls that only filter known data channels.

  3. Which tool is used to perform session hijacking by capturing and replaying network packets?

    Answer: Hamster and Ferret

    Hamster and Ferret are tools used together to sidejack HTTP sessions by capturing cookies from wireless traffic and replaying them to impersonate victims.

  4. What firewall type inspects traffic at Layer 7 and can identify and block specific applications regardless of port?

    Answer: Next-Generation Firewall (NGFW)

    A Next-Generation Firewall (NGFW) performs deep packet inspection at the application layer, enabling it to identify and control specific applications independent of port or protocol.

  5. Which technique do attackers use to bypass firewalls by encapsulating malicious traffic within an allowed protocol such as DNS or ICMP?

    Answer: Protocol Tunneling

    Protocol tunneling encapsulates unauthorized traffic inside permitted protocols (like DNS or ICMP), allowing it to pass through firewalls that only filter by protocol type.

  6. What is 'ARP spoofing' primarily used for in session hijacking attacks on a LAN?

    Answer: Associating the attacker's MAC with a legitimate IP to intercept traffic

    ARP spoofing sends fake ARP replies that associate the attacker's MAC address with a victim's IP, redirecting LAN traffic through the attacker for man-in-the-middle interception.