โ† All EJPT Flashcard Decks

Network Attacks Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Attacks flashcards as text
  1. Which command correctly performs OS detection and version scanning with Nmap against a single host?

    Answer: Both A and C are correct

    Both -sV -O and -A enable OS detection and service version scanning; -A additionally enables script scanning and traceroute.

  2. An attacker intercepts an NTLMv2 hash using Responder. What is the immediate next step to leverage this credential?

    Answer: Crack it offline with Hashcat or attempt an NTLM relay

    NTLMv2 hashes cannot be passed directly; they must either be cracked offline or relayed in real time using a tool like ntlmrelayx.

  3. What eJPT networking concept describes dividing a network into segments to limit lateral movement after a compromise?

    Answer: VLANs and network segmentation

    VLANs and network segmentation isolate hosts into separate broadcast domains, limiting an attacker's ability to pivot between systems.

  4. During a pentest, you discover a service on port 21. Which Nmap script would help enumerate anonymous FTP access?

    Answer: ftp-anon

    The ftp-anon NSE script checks whether an FTP server allows anonymous logins and lists accessible files.

  5. What is a 'man-in-the-browser' attack vector most closely related to on a local network?

    Answer: ARP poisoning redirecting traffic through the attacker

    On a LAN, ARP poisoning is the foundation for MITM attacks that can be extended to inspect or modify browser traffic passing through the attacker's machine.

  6. Which tool is used on Linux to relay intercepted NTLM authentication to another service in real time?

    Answer: Impacket's ntlmrelayx.py

    ntlmrelayx.py from the Impacket suite intercepts NTLM authentication and forwards it to target services like SMB or LDAP to gain access.

  7. In Wireshark, which display filter shows only TCP SYN packets (connection initiations)?

    Answer: tcp.flags.syn == 1 && tcp.flags.ack == 0

    Filtering for SYN=1 and ACK=0 isolates the first packet of the TCP handshake, excluding SYN-ACK responses.