Penetration Testing Tools & Methodologies Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Penetration Testing Tools & Methodologies flashcards as text
Which phase of a penetration test involves documenting vulnerabilities found and providing remediation guidance?
Answer: Reporting
The reporting phase summarizes findings, risk ratings, and actionable remediation steps for the client.
What is the primary function of John the Ripper?
Answer: Password hash cracking
John the Ripper is a password cracking tool that supports dictionary, brute-force, and rule-based attacks against hashed passwords.
In Metasploit, what is a 'payload'?
Answer: The code executed on the target after exploitation
A payload is the shellcode or code that runs on the target system after the exploit successfully executes.
Which tool is specifically designed for enumerating SMB shares and users on Windows systems?
Answer: Enum4linux
Enum4linux is a Linux-based tool that wraps Samba utilities to enumerate SMB shares, users, and policies on Windows/Samba hosts.
What does the 'LHOST' option in Metasploit specify?
Answer: The attacker's IP address where the reverse shell connects back
LHOST (Local Host) sets the attacker's IP address that the reverse payload will call back to after successful exploitation.
Which Nmap scan type sends only a SYN packet and is often called a 'stealth scan'?
Answer: -sS
The '-sS' SYN scan sends SYN packets and never completes the TCP handshake, making it less likely to appear in application logs.
What is the goal of the 'enumeration' phase in a penetration test?
Answer: Extracting detailed information about discovered services and users
Enumeration involves actively querying services to extract usernames, shares, OS versions, and other actionable details.