โ† All EJPT Flashcard Decks

Information Gathering and Reconnaissance Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Gathering and Reconnaissance flashcards as text
  1. Which DNS record type maps a domain name to an IPv6 address?

    Answer: AAAA record

    AAAA records map a domain name to a 128-bit IPv6 address, while A records map to IPv4.

  2. A penetration tester wants to find all subdomains of a target without directly querying the target's DNS servers. Which technique is best?

    Answer: Certificate transparency log search

    Certificate transparency logs (e.g., crt.sh) publicly record SSL/TLS certificates and reveal subdomains passively without alerting the target.

  3. What does the Nmap flag `-sV` accomplish during a scan?

    Answer: Performs version detection on open ports

    `-sV` probes open ports to determine service/version information running on those ports.

  4. Which WHOIS field would reveal when a domain registration is set to expire?

    Answer: Registry Expiry Date

    The Registry Expiry Date field in WHOIS records shows when the domain registration will expire.

  5. During passive reconnaissance, a tester finds an organization's LinkedIn page listing employee job titles and technologies used. This is an example of:

    Answer: OSINT gathering

    Gathering publicly available information from social media platforms like LinkedIn is a classic OSINT (Open Source Intelligence) technique.

  6. What is the primary purpose of a PTR (pointer) DNS record?

    Answer: Map IP address to domain name (reverse DNS)

    PTR records perform reverse DNS lookups, mapping an IP address back to a hostname.

  7. Which tool is commonly used for automated subdomain enumeration by brute-forcing with a wordlist?

    Answer: Gobuster

    Gobuster can brute-force subdomains using the `dns` mode with a wordlist to enumerate valid subdomains.