Information Gathering and Reconnaissance Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Information Gathering and Reconnaissance flashcards as text
What is the purpose of the `-A` flag in Nmap?
Answer: Enable aggressive mode: OS detection, version detection, scripts, and traceroute
Nmap's `-A` flag enables aggressive scanning including OS detection (`-O`), version detection (`-sV`), script scanning (`-sC`), and traceroute.
A DNS MX record is used to identify which of the following?
Answer: Mail exchange servers responsible for email delivery
MX (Mail Exchange) records specify the mail servers responsible for receiving email for a domain.
Which technique involves impersonating a vendor calling an employee to extract information about internal systems?
Answer: Pretexting
Pretexting involves creating a fabricated scenario (pretext) — such as impersonating a vendor — to manipulate someone into revealing information.
When running `nmap -p 1-1000 192.168.1.1`, what range of ports is scanned?
Answer: Ports 1 through 1000
The `-p 1-1000` flag explicitly instructs Nmap to scan TCP ports 1 through 1000 on the target.
What does the acronym OSINT stand for?
Answer: Open Source Intelligence
OSINT stands for Open Source Intelligence — information gathered from publicly available sources.
A tester notices TCP port 25 is open on a target server. What service is most likely running?
Answer: SMTP email server
Port 25 is the standard port for SMTP (Simple Mail Transfer Protocol), used for sending email.
Which of the following best describes the difference between active and passive reconnaissance?
Answer: Active directly interacts with the target; passive collects information without touching the target
Active reconnaissance involves direct interaction with target systems (e.g., port scanning), while passive uses publicly available data without contacting the target.