โ† All EJPT Flashcard Decks

Information Gathering and Reconnaissance Flashcards

6 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Information Gathering and Reconnaissance flashcards as text
  1. What is the primary purpose of passive reconnaissance in penetration testing?

    Answer: To gather information without directly interacting with the target

    Passive reconnaissance collects information about a target without direct interaction, reducing the chance of detection.

  2. Which tool is commonly used for DNS enumeration during information gathering?

    Answer: nslookup and dig

    nslookup and dig are standard DNS query tools used to enumerate DNS records and discover subdomains during reconnaissance.

  3. What is OSINT in the context of penetration testing?

    Answer: Open Source Intelligence gathering from publicly available information

    OSINT involves collecting intelligence from publicly available sources such as websites, social media, and public records.

  4. What type of information does a WHOIS lookup provide?

    Answer: Domain registration details including registrant and contact information

    WHOIS lookups reveal domain registration information including registrant details, nameservers, and registration dates.

  5. What is the purpose of port scanning during active reconnaissance?

    Answer: To identify open ports and running services on target systems

    Port scanning identifies open ports and running services, revealing the attack surface and potential entry points.

  6. Which reconnaissance technique involves examining website source code and headers?

    Answer: Web application fingerprinting

    Web application fingerprinting examines HTTP headers, source code, and responses to identify technologies and versions in use.