โ† All EJPT Flashcard Decks

Network Security & Vulnerability Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Vulnerability flashcards as text
  1. A tester wants to identify all open UDP ports on a target. Which Nmap flag is used?

    Answer: -sU

    The `-sU` flag triggers a UDP scan; Nmap sends empty UDP packets and interprets ICMP Port Unreachable responses as closed ports and no response as open|filtered.

  2. Which of the following BEST describes a 'null session' vulnerability in older Windows systems?

    Answer: Anonymous connection to the IPC$ share allowing enumeration of users and shares

    A null session allows unauthenticated SMB connections to IPC$ in older Windows, enabling enumeration of usernames, shares, and domain information.

  3. What information does the 'Banner Grabbing' technique provide during reconnaissance?

    Answer: Service name, version, and sometimes OS information from a network service

    Banner grabbing retrieves the service banner (text sent by a service on connection), which often reveals the service name, version number, and OS details useful for identifying vulnerabilities.

  4. During a network scan, Nmap reports a port as 'filtered'. What does this mean?

    Answer: A firewall or filter is blocking probe packets, preventing determination of state

    A filtered port status means Nmap's probes are being blocked by a packet filter or firewall, so Nmap cannot determine if the port is open or closed.

  5. Which vulnerability class involves sending more data than a buffer can hold, potentially overwriting adjacent memory?

    Answer: Buffer Overflow

    A buffer overflow occurs when input exceeds the allocated buffer size, overwriting adjacent memory regions and potentially allowing arbitrary code execution.

  6. A pentester needs to check whether SMB signing is disabled on a target. Which tool is most appropriate?

    Answer: Nmap with smb-security-mode script

    The Nmap NSE script `smb-security-mode` checks SMB message signing configuration, revealing whether signing is required, enabled-but-not-required, or disabled.

  7. What is the default port used by the Remote Desktop Protocol (RDP)?

    Answer: 3389

    RDP listens on TCP port 3389 by default; knowing this allows penetration testers to identify potential remote-access attack surfaces during port scans.