← All EJPT Flashcard Decks

Network Attacks Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Network Attacks flashcards as text
  1. Which tool is most commonly used to perform a SYN flood DoS attack during a penetration test?

    Answer: hping3

    hping3 can craft and send large volumes of SYN packets to a target, making it the standard tool for SYN flood testing.

  2. What is the primary goal of an ARP cache poisoning attack?

    Answer: Associate the attacker's MAC with a legitimate IP

    ARP poisoning overwrites a victim's ARP cache so traffic destined for a legitimate IP is sent to the attacker's MAC address instead.

  3. During an MITM attack using Ettercap, what must be enabled on the attacker's Linux system for forwarded traffic to reach its destination?

    Answer: IP forwarding via /proc/sys/net/ipv4/ip_forward

    Without enabling IP forwarding, packets intercepted by the attacker are dropped instead of relayed, breaking connectivity and alerting victims.

  4. Which eJPT-relevant attack exploits the trust relationship between a DHCP client and server to redirect traffic?

    Answer: DHCP spoofing (rogue DHCP)

    A rogue DHCP server responds to client requests first, assigning itself as the default gateway to redirect all client traffic through the attacker.

  5. What Nmap flag is used to perform a NULL scan?

    Answer: -sN

    The -sN flag tells Nmap to send TCP packets with no flags set, which is the definition of a NULL scan.

  6. When performing password spraying against a network service, what distinguishes it from a traditional brute-force attack?

    Answer: It uses a single password against many usernames

    Password spraying tries one common password across many accounts to avoid lockout policies that trigger on repeated failures to a single account.

  7. Which protocol does mDNS (Multicast DNS) use, making it susceptible to spoofing on local networks?

    Answer: UDP port 5353

    mDNS operates over UDP port 5353 using multicast, and because it lacks authentication, attackers can send forged responses to redirect traffic.