โ† All EJPT Flashcard Decks

Network Attacks Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Attacks flashcards as text
  1. What does the Responder tool primarily exploit on Windows networks?

    Answer: LLMNR and NBT-NS name resolution broadcasts

    Responder listens for LLMNR and NBT-NS broadcast queries and responds with the attacker's IP to capture NTLMv2 hashes.

  2. In a network capture, you see repeated ICMP Type 3 Code 3 messages. What do these indicate?

    Answer: Port unreachable

    ICMP Type 3 Code 3 means 'Destination Port Unreachable,' typically seen when a UDP packet hits a closed port.

  3. Which attack technique involves sending a large number of UDP packets to random ports on a target to consume resources?

    Answer: UDP flood

    A UDP flood overwhelms a target by forcing it to process and respond with ICMP port-unreachable messages for each unexpected UDP packet received.

  4. When using Wireshark to analyze traffic during an ARP spoofing attack, what is the key indicator in the ARP packets?

    Answer: Two different IPs sharing the same MAC address

    ARP spoofing is revealed when two different IP addresses are mapped to the same MAC address in ARP reply packets.

  5. What is CAM table overflow and which tool is commonly used to execute it?

    Answer: Flooding a switch with fake MACs to force hub behavior; macof

    macof sends thousands of frames with random MACs, filling the switch CAM table so the switch falls back to flooding all traffic to every port.

  6. Which Metasploit auxiliary module is used to scan for hosts running SMB on port 445?

    Answer: auxiliary/scanner/smb/smb_version

    The smb_version auxiliary module probes port 445 on target hosts and reports the SMB version and OS details.

  7. What type of scan does Nmap use by default when run without the -s flag as a non-root user?

    Answer: TCP connect scan

    Non-root users cannot craft raw packets, so Nmap falls back to a full TCP connect scan using the OS's connect() system call.