โ† All Certified Ethical Hacker Flashcard Decks

Network Security and Scanning Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Network Security and Scanning flashcards as text
  1. What is the purpose of a SYN scan (half-open scan) in network reconnaissance?

    Answer: To identify open ports without completing the TCP handshake, making it stealthier

    A SYN scan sends SYN packets and analyzes responses (SYN-ACK = open, RST = closed) without completing the three-way handshake, making it faster and harder to detect than full connect scans.

  2. What is the difference between active and passive reconnaissance?

    Answer: Active directly interacts with the target system; passive gathers information without direct contact

    Active reconnaissance involves direct interaction with the target (port scanning, vulnerability scanning), while passive reconnaissance gathers publicly available information (WHOIS, social media, DNS records) without alerting the target.

  3. What is OS fingerprinting in ethical hacking?

    Answer: Identifying the target's operating system by analyzing network packet characteristics

    OS fingerprinting analyzes unique characteristics of network packets (TTL values, TCP window size, DF bit) to identify the target's operating system and version, using tools like Nmap.

  4. What is a vulnerability assessment versus a penetration test?

    Answer: VA identifies vulnerabilities without exploitation; a pentest actively exploits vulnerabilities to prove impact

    A vulnerability assessment scans and identifies potential security weaknesses, while a penetration test goes further by actively attempting to exploit discovered vulnerabilities to demonstrate real-world impact.

  5. What is banner grabbing and what information does it reveal?

    Answer: Connecting to services to capture their version information and software details

    Banner grabbing connects to network services (HTTP, FTP, SMTP) and captures the service banner which typically reveals the software name, version, and sometimes OS information, helping identify exploitable vulnerabilities.

  6. What is the purpose of enumeration in the ethical hacking methodology?

    Answer: Extracting detailed information like usernames, shares, and services from a target system

    Enumeration involves establishing active connections to target systems to extract detailed information including user accounts, network shares, group memberships, SNMP data, and DNS zone transfers.