Mixed Deck — All EJPT Topics Flashcards
100 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All EJPT Topics flashcards as text
Which Meterpreter command captures screenshots of the victim's desktop?
Answer: screenshot
The `screenshot` command in Meterpreter captures the current state of the victim's desktop and saves it locally for the attacker.
In a dictionary attack against a login form, what is the attacker using as input?
Answer: A precompiled list of common passwords/words
A dictionary attack uses a wordlist of likely passwords (common words, phrases, known breached passwords) rather than pure random guessing.
During footprinting, a tester uses Google dork `filetype:pdf site:target.com`. What is the goal?
Answer: Find PDF documents hosted on target.com
The `filetype:pdf site:target.com` Google dork searches for PDF files indexed by Google that belong to target.com.
What is OSINT in the context of penetration testing?
Answer: Open Source Intelligence gathering from publicly available information
OSINT involves collecting intelligence from publicly available sources such as websites, social media, and public records.
A network segment uses the address 10.10.10.0/24. How many usable host IP addresses does this subnet provide?
Answer: 254
A /24 subnet has 256 total addresses; subtracting the network address (10.10.10.0) and broadcast address (10.10.10.255) leaves 254 usable host addresses.
In Metasploit, what is a 'staged' payload?
Answer: A small initial stager that downloads and executes the full payload
A staged payload uses a tiny stager (stage 0) that connects back to the attacker and downloads the larger main payload into memory.
In Nessus scan results, what does a 'High' severity finding typically indicate?
Answer: A vulnerability that is easily exploitable and could lead to significant compromise
High severity findings represent vulnerabilities with significant exploitability or impact, often with known exploits, requiring prompt remediation.
What type of information does a WHOIS lookup provide?
Answer: Domain registration details including registrant and contact information
WHOIS lookups reveal domain registration information including registrant details, nameservers, and registration dates.
During scoping, a client wants to include a third-party SaaS platform they use. What must you verify before including it?
Answer: That the client has written authorization from the third-party vendor to test their platform
Third-party systems require explicit written authorization from their owners before they can be included in a penetration test scope.
Which Windows registry hive stores user account password hashes locally?
Answer: HKEY_LOCAL_MACHINE\SAM
The SAM (Security Account Manager) hive under HKEY_LOCAL_MACHINE stores NTLM hashes for local Windows user accounts.
In eJPT certification, what does redundancy in system design primarily provide?
Answer: Fault tolerance and high availability
Redundancy provides fault tolerance by ensuring that if one component fails, backup components maintain system availability.
What is a typical tool used for password cracking in penetration testing?
Answer: John the Ripper or Hashcat.
John the Ripper and Hashcat are powerful and widely recognized tools specifically designed for password cracking. They work by taking hashed passwords (often obtained from compromised systems) and attempting to guess the original plaintext password using various techniques like dictionary attacks, brute-force attacks, and rainbow tables. These tools are crucial for penetration testers to assess the strength of password policies.
What is the purpose of the `-A` flag in Nmap?
Answer: Enable aggressive mode: OS detection, version detection, scripts, and traceroute
Nmap's `-A` flag enables aggressive scanning including OS detection (`-O`), version detection (`-sV`), script scanning (`-sC`), and traceroute.
What is the primary difference between a vulnerability assessment and a penetration test?
Answer: A vulnerability assessment identifies weaknesses while a penetration test actively exploits them to demonstrate real-world impact
Vulnerability assessments identify and classify weaknesses, while penetration tests go further by exploiting vulnerabilities to prove they are truly exploitable.
Which tool is specifically designed for enumerating SMB shares and users on Windows systems?
Answer: Enum4linux
Enum4linux is a Linux-based tool that wraps Samba utilities to enumerate SMB shares, users, and policies on Windows/Samba hosts.
Which approach best demonstrates mastery of attacks and exploits in eJPT practice?
Answer: Applying principles to novel situations with sound judgment
True mastery involves understanding underlying principles well enough to apply them to new and unfamiliar situations with professional judgment.
What does a vulnerability scan report typically include that helps prioritize remediation efforts?
Answer: Severity ratings and CVSS scores for each finding
Vulnerability scan reports assign severity ratings and CVSS scores to each finding, enabling security teams to prioritize patching the highest-risk issues first.
During a vulnerability scan, you discover an SMB service running on port 445. Which well-known vulnerability should you specifically check for on unpatched Windows systems?
Answer: EternalBlue (MS17-010)
EternalBlue (MS17-010) is a critical SMB vulnerability exploited by WannaCry and NotPetya, and is a standard check when SMB is discovered on unpatched Windows hosts.
Which WHOIS field would reveal when a domain registration is set to expire?
Answer: Registry Expiry Date
The Registry Expiry Date field in WHOIS records shows when the domain registration will expire.
Which of the following best describes 'remediation verification' in the context of penetration testing?
Answer: A follow-up assessment to confirm that reported vulnerabilities have been successfully fixed
Remediation verification (also called retesting) confirms that the client's fixes actually close the vulnerabilities identified in the original penetration test.