Network Security & Vulnerability Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Security & Vulnerability flashcards as text
Which Nmap scan type sends TCP packets with the SYN flag set and does NOT complete the three-way handshake?
Answer: SYN scan (-sS)
SYN scan (-sS) sends a SYN packet and, upon receiving SYN/ACK, immediately sends RST, never completing the handshake — making it stealthier than a full connect scan.
An attacker captures traffic and sees ARP replies associating the gateway IP with the attacker's MAC address. What attack is occurring?
Answer: ARP poisoning
ARP poisoning (ARP spoofing) involves sending unsolicited ARP replies to associate the attacker's MAC with a legitimate IP, enabling man-in-the-middle interception.
What does a CVE score of 9.8 indicate about a vulnerability?
Answer: Critical severity, likely remotely exploitable with no authentication required
A CVSS score of 9.8 is near-maximum and typically indicates a critical, network-exploitable vulnerability requiring no privileges or user interaction.
Which protocol does Nmap use when performing host discovery with the -sn flag against a local subnet?
Answer: ICMP Echo Request and ARP
On a local subnet, Nmap's ping scan (-sn) uses ARP requests to discover live hosts; on remote networks it uses ICMP Echo, TCP SYN/ACK, and ICMP timestamp requests.
A penetration tester runs: `nmap -sV -p 21 192.168.1.10` and sees 'vsftpd 2.3.4'. Why is this significant?
Answer: vsftpd 2.3.4 contains a backdoor that opens a shell on port 6200
vsftpd 2.3.4 was compromised in a supply-chain attack; it contains a backdoor triggered by a smiley-face username that opens a root shell on port 6200.
What is the purpose of the Nmap Scripting Engine (NSE)?
Answer: To extend Nmap with scripts for tasks such as vuln detection, brute-forcing, and service enumeration
NSE allows users to write and run Lua scripts that automate tasks like version detection, vulnerability checking, and authentication brute-forcing directly within Nmap.
Which technique allows an attacker to map internal network topology by analyzing TTL values in ICMP Time Exceeded messages?
Answer: Traceroute
Traceroute exploits decreasing TTL values; each router decrements the TTL and, when it hits zero, sends back an ICMP Time Exceeded message revealing the router's IP.