Network Security and Scanning Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security and Scanning flashcards as text
Which scanning technique uses banner grabbing to gather information?
Answer: Connecting to a service to read its response header
Banner grabbing connects to a service (e.g., via Telnet or netcat) to read identifying header text.
Why is a UDP scan generally slower and less reliable than a TCP scan?
Answer: UDP is connectionless and open ports often send no response
UDP is connectionless, so open ports frequently stay silent, forcing slow timeout-based inference.
What is the main goal of network enumeration after scanning?
Answer: To extract usernames, shares, and services from identified hosts
Enumeration actively extracts resources like usernames, shares, and services from discovered systems.
Which tool is commonly used to capture and analyze network packets?
Answer: Wireshark
Wireshark is a packet capture and protocol analyzer used to inspect network traffic.
An attacker performs a DNS zone transfer (AXFR). What is the risk if it succeeds?
Answer: The full list of DNS records for the domain is exposed
A successful zone transfer hands over the complete DNS records, revealing internal hostnames and structure.
What does TTL (Time To Live) manipulation help an attacker achieve?
Answer: Evading some IDS by controlling packet hop expiration
Crafting TTL values can cause packets to expire before reaching the IDS, aiding evasion.
Which Nmap timing template is the most aggressive and fastest?
Answer: -T5 (insane)
-T5 (insane) is the fastest, most aggressive timing template at the cost of accuracy and stealth.