312-50 exam dumps

312-50 practice question 254 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 254

Single answer▪ Session Hijacking Tools

During an authorized internal assessment, you are connected to the same switched office network as several users accessing an internal web application over plain HTTP. Your goal is to demonstrate the risk of session hijacking by capturing a valid session cookie from a victim after obtaining a position to observe or relay their traffic. Which tool is specifically designed to intercept HTTP requests and extract session identifiers such as cookies for this purpose?

  1. A

    Ettercap

  2. B

    Burp Suite

  3. C

    HTTrack

  4. D

    BetterCAP

Show answer and explanation

Correct answer: A

Explanation

This question tests whether the candidate can distinguish between web testing tools and network-based session hijacking tools. In a switched LAN, an attacker typically needs a man-in-the-middle position first, often through techniques such as ARP spoofing/poisoning, before intercepting unencrypted HTTP traffic. Ettercap is widely recognized in ethical hacking training and CEH-style objectives as a session hijacking-related tool because it combines MITM capability with protocol analysis and data extraction. Burp Suite is excellent for analyzing and manipulating the tester's own proxied HTTP/S sessions, but it does not by itself capture another host's traffic from the LAN. HTTrack is unrelated to session interception. BetterCAP has relevant capabilities, but CEH-oriented exam questions often expect recognition of Ettercap as the classic tool associated with session hijacking on local networks. Best practice references include avoiding plain HTTP, enforcing HTTPS everywhere, setting Secure and HttpOnly cookie attributes, using HSTS, segmenting networks, and deploying switch protections such as Dynamic ARP Inspection to reduce the risk of session hijacking.

  • A. Correct.

    Correct. Ettercap is a classic man-in-the-middle and LAN attack tool commonly used in session hijacking demonstrations on local networks. After ARP poisoning or similar MITM positioning, it can intercept traffic and includes features for parsing data such as HTTP credentials and session cookies from unencrypted traffic. In a plain HTTP environment, this makes it well suited for capturing session identifiers during a controlled assessment.

  • B. Incorrect.

    Incorrect. Burp Suite is primarily a web application testing proxy used between the tester's browser and the target application. While it can inspect cookies and manipulate sessions for traffic that passes through the proxy, it is not specifically intended to place the tester into a man-in-the-middle position on a switched LAN to capture another user's session traffic. A candidate might choose this because Burp is strongly associated with cookies and session testing, but the scenario focuses on intercepting a victim's traffic on the network.

  • C. Incorrect.

    Incorrect. HTTrack is a website mirroring and offline browsing tool. It copies site content for local viewing but is not used to intercept live network traffic or capture session cookies from another user's connection. This distractor targets the misconception that any web-related tool can be applied to session attacks.

  • D. Incorrect.

    Incorrect. BetterCAP is also a valid network attack and MITM framework and can be used in traffic interception scenarios, but the question asks for the tool specifically known in CEH contexts for intercepting HTTP requests and extracting session identifiers such as cookies. In exam-focused treatment of session hijacking tools, Ettercap is the more direct and canonical answer. A student might choose BetterCAP because it is a modern alternative with similar capabilities, but the phrasing points to the classic session hijacking tool typically emphasized in CEH preparation.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam