← All EJPT Flashcard Decks

Information Gathering and Reconnaissance Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Information Gathering and Reconnaissance flashcards as text
  1. What is the purpose of the `-A` flag in Nmap?

    Answer: Enable aggressive mode: OS detection, version detection, scripts, and traceroute

    Nmap's `-A` flag enables aggressive scanning including OS detection (`-O`), version detection (`-sV`), script scanning (`-sC`), and traceroute.

  2. A DNS MX record is used to identify which of the following?

    Answer: Mail exchange servers responsible for email delivery

    MX (Mail Exchange) records specify the mail servers responsible for receiving email for a domain.

  3. Which technique involves impersonating a vendor calling an employee to extract information about internal systems?

    Answer: Pretexting

    Pretexting involves creating a fabricated scenario (pretext) — such as impersonating a vendor — to manipulate someone into revealing information.

  4. When running `nmap -p 1-1000 192.168.1.1`, what range of ports is scanned?

    Answer: Ports 1 through 1000

    The `-p 1-1000` flag explicitly instructs Nmap to scan TCP ports 1 through 1000 on the target.

  5. What does the acronym OSINT stand for?

    Answer: Open Source Intelligence

    OSINT stands for Open Source Intelligence — information gathered from publicly available sources.

  6. A tester notices TCP port 25 is open on a target server. What service is most likely running?

    Answer: SMTP email server

    Port 25 is the standard port for SMTP (Simple Mail Transfer Protocol), used for sending email.

  7. Which of the following best describes the difference between active and passive reconnaissance?

    Answer: Active directly interacts with the target; passive collects information without touching the target

    Active reconnaissance involves direct interaction with target systems (e.g., port scanning), while passive uses publicly available data without contacting the target.