โ† All EJPT Flashcard Decks

Attacks and Exploits Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Attacks and Exploits flashcards as text
  1. Which Metasploit command is used to search for a specific exploit module by name?

    Answer: search

    The `search` command in msfconsole allows you to search for modules by keyword, name, CVE, or platform.

  2. What type of payload establishes a connection FROM the target machine TO the attacker?

    Answer: Reverse shell

    A reverse shell has the victim connect back to the attacker's machine, which helps bypass firewalls that block inbound connections.

  3. In an ARP poisoning attack, what does the attacker send to redirect traffic through their machine?

    Answer: Gratuitous ARP replies with the attacker's MAC

    The attacker sends gratuitous ARP replies associating the gateway IP with their own MAC address, causing victims to send traffic through the attacker.

  4. Which SQL injection technique retrieves data by causing the database to generate time delays?

    Answer: Time-based blind injection

    Time-based blind SQL injection uses functions like SLEEP() or WAITFOR DELAY to infer data based on how long the response takes.

  5. What is the primary purpose of a staged Metasploit payload (e.g., windows/meterpreter/reverse_tcp)?

    Answer: To send a small stager first that downloads the full payload

    Staged payloads send a tiny initial stager that connects back to Metasploit and downloads the full Meterpreter payload, keeping the initial shellcode small.

  6. Which command in Meterpreter is used to escalate privileges by attempting known local exploits?

    Answer: getsystem

    `getsystem` attempts various privilege escalation techniques automatically to gain SYSTEM-level access on Windows.

  7. What does a 'bind shell' payload do differently from a reverse shell?

    Answer: It listens on a port on the target for the attacker to connect to

    A bind shell opens a listening port on the compromised target, and the attacker connects to that port to get a shell.