Network Attacks Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Attacks flashcards as text
Which network attack exploits the way IP fragmentation reassembly works by sending overlapping fragments that confuse the target OS?
Answer: Teardrop attack
The Teardrop attack sends malformed IP fragments with overlapping offsets that crash or freeze vulnerable OS reassembly code.
What is the purpose of using a 'decoy' in an Nmap scan (the -D flag)?
Answer: Make the scan appear to originate from multiple hosts
The -D flag causes Nmap to spoof packets from decoy IPs alongside the real source, making it harder for defenders to identify the true scanner.
A penetration tester runs: arpspoof -i eth0 -t 192.168.1.5 192.168.1.1. What does this command do?
Answer: Tells 192.168.1.5 that the attacker's MAC is 192.168.1.1's MAC
This arpspoof command sends fake ARP replies to 192.168.1.5 claiming the attacker's MAC is associated with the gateway IP 192.168.1.1.
What is the key difference between a passive network reconnaissance technique and an active one?
Answer: Passive does not send packets to the target; active does
Passive reconnaissance gathers information without touching the target (e.g., OSINT, packet sniffing), while active reconnaissance sends packets directly to target systems.
Which Metasploit module category is used to gain an initial foothold by exploiting a vulnerability?
Answer: Exploit
Exploit modules in Metasploit attack specific vulnerabilities in target services to deliver a payload and establish a session.
When a TCP RST packet is received in response to a probe during a port scan, what is the port state?
Answer: Closed
A TCP RST response means the port is closed — the service is not listening, but the host is reachable and actively rejecting the connection.
Which attack sends an ICMP echo request to a broadcast address with a spoofed source IP of the victim, causing many hosts to reply to the victim?
Answer: Smurf attack
The Smurf attack amplifies traffic by spoofing the victim's IP as the source of ICMP broadcast pings, causing the entire subnet to flood the victim with replies.