Network Security & Vulnerability Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Vulnerability flashcards as text
A tester wants to identify all open UDP ports on a target. Which Nmap flag is used?
Answer: -sU
The `-sU` flag triggers a UDP scan; Nmap sends empty UDP packets and interprets ICMP Port Unreachable responses as closed ports and no response as open|filtered.
Which of the following BEST describes a 'null session' vulnerability in older Windows systems?
Answer: Anonymous connection to the IPC$ share allowing enumeration of users and shares
A null session allows unauthenticated SMB connections to IPC$ in older Windows, enabling enumeration of usernames, shares, and domain information.
What information does the 'Banner Grabbing' technique provide during reconnaissance?
Answer: Service name, version, and sometimes OS information from a network service
Banner grabbing retrieves the service banner (text sent by a service on connection), which often reveals the service name, version number, and OS details useful for identifying vulnerabilities.
During a network scan, Nmap reports a port as 'filtered'. What does this mean?
Answer: A firewall or filter is blocking probe packets, preventing determination of state
A filtered port status means Nmap's probes are being blocked by a packet filter or firewall, so Nmap cannot determine if the port is open or closed.
Which vulnerability class involves sending more data than a buffer can hold, potentially overwriting adjacent memory?
Answer: Buffer Overflow
A buffer overflow occurs when input exceeds the allocated buffer size, overwriting adjacent memory regions and potentially allowing arbitrary code execution.
A pentester needs to check whether SMB signing is disabled on a target. Which tool is most appropriate?
Answer: Nmap with smb-security-mode script
The Nmap NSE script `smb-security-mode` checks SMB message signing configuration, revealing whether signing is required, enabled-but-not-required, or disabled.
What is the default port used by the Remote Desktop Protocol (RDP)?
Answer: 3389
RDP listens on TCP port 3389 by default; knowing this allows penetration testers to identify potential remote-access attack surfaces during port scans.