Penetration Testing Tools & Methodologies Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Penetration Testing Tools & Methodologies flashcards as text
Which command in msfconsole sets a module option value?
Answer: set
The 'set' command assigns a value to a module option (e.g., 'set RHOSTS 192.168.1.1') within msfconsole.
What type of attack does Hydra primarily perform?
Answer: Online password brute-force attacks
Hydra is a fast, parallelized login cracker that performs brute-force and dictionary attacks against online services.
In web application testing, what does Nikto scan for?
Answer: Known web server vulnerabilities, misconfigurations, and dangerous files
Nikto is a web server scanner that checks for outdated software, dangerous files, and common misconfigurations.
What is the purpose of using a 'staged' payload in Metasploit?
Answer: To send a small initial stager that downloads the full payload, reducing initial size
Staged payloads use a tiny stager (stage 0) to connect back and fetch the full-featured stage 1 payload, helping bypass size restrictions.
Which protocol does ARP spoofing attack, and what is its primary goal in a pentest?
Answer: ARP; associate the attacker's MAC with a legitimate IP to intercept traffic
ARP spoofing poisons the ARP cache so that traffic meant for a legitimate IP is sent to the attacker's machine instead.
What does the Metasploit 'meterpreter' provide over a basic shell?
Answer: An advanced in-memory payload with file transfer, pivoting, and post-exploitation modules
Meterpreter runs entirely in memory, avoids writing to disk, and provides rich post-exploitation capabilities like file operations and pivoting.
Which Nmap script category is most useful for detecting known vulnerabilities during a scan?
Answer: vuln
The 'vuln' NSE script category runs checks for known CVEs and misconfigurations against detected services.