← All EJPT Flashcard Decks

Information Gathering and Reconnaissance Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Information Gathering and Reconnaissance flashcards as text
  1. What is the function of the `host` command in Linux during DNS reconnaissance?

    Answer: Perform DNS lookups to resolve domain names to IP addresses

    The `host` command performs DNS lookups, resolving domain names to IPs and querying various DNS record types.

  2. During reconnaissance, a tester discovers the target uses Cloudflare. What challenge does this present?

    Answer: Cloudflare may mask the real origin IP, making it harder to identify the actual server

    Cloudflare acts as a reverse proxy, hiding the origin server's real IP address behind Cloudflare's IPs, complicating direct targeting.

  3. Which Nmap output format option saves results in all major formats simultaneously?

    Answer: -oA

    `-oA ` saves scan results in normal, XML, and grepable formats simultaneously with the specified base filename.

  4. What type of information can be extracted from website metadata (e.g., PDF, DOCX files) during OSINT?

    Answer: Author names, software versions, and GPS coordinates

    Document metadata can reveal author names, creation software/versions, company names, and sometimes GPS coordinates embedded in images.

  5. A tester runs `nmap -sU -p 53,161 10.10.10.1`. Which protocols are being probed?

    Answer: UDP DNS and SNMP

    UDP port 53 is DNS and UDP port 161 is SNMP; the `-sU` flag specifies UDP scanning.

  6. Which search engine operator would a tester use to find login pages indexed by Google on a target domain?

    Answer: site:target.com inurl:login

    `site:target.com inurl:login` restricts results to the target domain and filters for URLs containing 'login'.

  7. What is the risk of performing a DNS zone transfer (`AXFR`) against a misconfigured DNS server?

    Answer: It exposes the complete list of DNS records for the domain to unauthorized parties

    A successful AXFR zone transfer returns all DNS records (hosts, subdomains, IPs) for the zone, giving attackers a full map of the target's infrastructure.