โ† All EJPT Flashcard Decks

Penetration Testing Tools & Methodologies Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Penetration Testing Tools & Methodologies flashcards as text
  1. What is the eJPT exam primarily focused on testing?

    Answer: Junior-level practical penetration testing skills including scanning, enumeration, and basic exploitation

    The eJPT certifies foundational hands-on penetration testing skills covering reconnaissance, scanning, exploitation, and reporting.

  2. Which tool would you use to perform directory brute-forcing on a web server?

    Answer: Gobuster

    Gobuster performs fast directory and file brute-forcing against web servers using wordlists to discover hidden content.

  3. What is the difference between a vulnerability scan and a penetration test?

    Answer: A vulnerability scan identifies potential weaknesses while a penetration test actively exploits them to confirm impact

    Vulnerability scanning identifies and reports potential issues, whereas a penetration test goes further by actually exploiting confirmed vulnerabilities.

  4. In the context of web application testing, what is a 'directory traversal' vulnerability?

    Answer: Accessing files outside the web root by manipulating file path inputs with sequences like '../'

    Directory traversal exploits insufficient input validation to navigate the file system beyond the intended web root using '../' sequences.

  5. Which Metasploit module type is used for gathering information without exploiting a vulnerability?

    Answer: Auxiliary

    Auxiliary modules perform scanning, fuzzing, sniffing, and service enumeration without exploiting a target.

  6. What is the purpose of running 'netstat -an' on a compromised Windows host during post-exploitation?

    Answer: View active network connections and listening ports to identify pivot targets

    Netstat -an displays all active TCP/UDP connections and listening ports, revealing internal services and potential pivot paths.

  7. Which scanning technique involves sending packets with no flags set to evade detection?

    Answer: NULL scan (-sN)

    A NULL scan sends TCP packets with no flags set; some firewalls and IDS systems do not log flagless packets, aiding evasion.