Penetration Testing Tools & Methodologies Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Penetration Testing Tools & Methodologies flashcards as text
Which Metasploit command searches for modules related to a specific vulnerability or service?
Answer: search
The 'search' command in msfconsole lets you find modules by keyword, CVE, or platform.
What does the Nmap flag '-sU' perform?
Answer: UDP scan
The '-sU' flag instructs Nmap to perform a UDP port scan instead of the default TCP scan.
In a penetration test, what is 'pivoting'?
Answer: Using a compromised host to attack other internal systems
Pivoting uses a compromised machine as a relay to reach and attack other network segments not directly accessible.
Which tool is commonly used for capturing and analyzing network packets during a penetration test?
Answer: Wireshark
Wireshark is a network protocol analyzer used to capture and inspect packets in real time.
What is the purpose of a 'bind shell' in post-exploitation?
Answer: The target machine opens a listener and the attacker connects to it
A bind shell opens a listening port on the target, allowing the attacker to connect inbound to gain shell access.
Which Nmap option is used to detect the operating system of a target host?
Answer: -O
The '-O' flag enables Nmap's OS detection engine, which fingerprints the target's operating system.
What does SQLmap's '--dbs' flag do?
Answer: Enumerates available databases
The '--dbs' flag tells SQLmap to enumerate and list all databases accessible on the target server.