eJPT (eLearnSecurity Junior Penetration Tester) — Questions and Answers
Question 1: When testing authentication, you notice the application uses Base64-encoded values in a cookie rather than a session ID. Why is this a security concern?
- Base64 cookies bypass HttpOnly restrictions automatically
- Base64 increases cookie size beyond browser limits
- Base64 is encoding, not encryption — the data can be trivially decoded to reveal sensitive information (Correct answer)
- Base64-encoded cookies are incompatible with HTTPS
Correct answer: Base64 is encoding, not encryption — the data can be trivially decoded to reveal sensitive information
Base64 is an encoding scheme, not encryption — anyone who intercepts the cookie can decode it instantly, potentially exposing usernames, roles, or other sensitive data.
Question 2: What is the primary advantage of a PMKID attack over a traditional WPA2 4-way handshake capture attack?
- It requires capturing traffic from at least 10 connected clients
- It only requires physical access to the router
- It only works against WPA1 networks with TKIP encryption
- It can crack the password without waiting for any client to connect (Correct answer)
Correct answer: It can crack the password without waiting for any client to connect
The PMKID attack retrieves a hash directly from the AP's first EAPOL frame, eliminating the need to wait for a legitimate client to connect and complete a handshake.
Question 3: A pentester has valid credentials for a Windows domain account. Which technique allows them to execute commands on a remote Windows host using those credentials without a pre-existing shell?
- Kerberoasting
- LLMNR poisoning
- ARP spoofing
- PsExec lateral movement via SMB (Correct answer)
Correct answer: PsExec lateral movement via SMB
PsExec-style lateral movement uses valid credentials to authenticate over SMB, upload a service binary, and execute commands on the remote host.
Question 4: A junior penetration tester is tasked with finding subdomains for a target domain. Which of the following tools is specifically designed for subdomain enumeration using various public sources and brute-force techniques?
- Wireshark
- Nmap
- Sublist3r (Correct answer)
- Metasploit
Correct answer: Sublist3r
Sublist3r is a Python-based tool specifically created to enumerate subdomains of websites by leveraging OSINT. It aggregates results from various search engines like Google and Bing, as well as services like VirusTotal and Netcraft, and can also perform brute-forcing to find more subdomains. Nmap is for network scanning, Wireshark for packet analysis, and Metasploit is an exploitation framework.
Question 5: During enumeration you run 'netdiscover -r 192.168.1.0/24'. What is this tool primarily used for?
- Enumerate SMB shares
- Brute-force SSH logins
- Perform DNS lookups
- ARP-based host discovery on a local network (Correct answer)
Correct answer: ARP-based host discovery on a local network
netdiscover uses ARP requests to discover live hosts on a local subnet, making it effective for internal network reconnaissance.
Question 6: What does the 'check' command do in Metasploit before running an exploit?
- Verifies the target is vulnerable without exploiting it (Correct answer)
- Runs the exploit in safe mode
- Validates module syntax
- Checks if the payload is compatible
Correct answer: Verifies the target is vulnerable without exploiting it
The 'check' command tests whether the target is vulnerable without actually launching the exploit.
Question 7: What tool does the course focus on using efficiently?
- Burp Suite
- Metasploit
- nmap (Correct answer)
- Wireshark
Correct answer: nmap
The eJPT course places a significant emphasis on the efficient use of `nmap` because it is a fundamental and powerful tool for network discovery and security auditing. `nmap` allows penetration testers to identify live hosts, open ports, services running on those ports, operating systems, and more, which are crucial initial steps in any penetration test. Mastering `nmap` is essential for effective reconnaissance and vulnerability identification.
Question 8: During a web application reconnaissance, a tester discovers a `robots.txt` file. What is the primary purpose of this file from a security perspective?
- To provide a list of all vulnerabilities present on the web server.
- To suggest which directories search engines should not index, potentially revealing sensitive paths. (Correct answer)
- To block malicious crawlers from accessing the website.
- To list all the administrator usernames and passwords.
Correct answer: To suggest which directories search engines should not index, potentially revealing sensitive paths.
The `robots.txt` file is used to instruct search engine crawlers on which pages or directories of a website should not be indexed. For a penetration tester, this can be a valuable source of information, as it often points to directories that the website owner wants to keep private, such as administrative panels or resource folders, which may not be as hardened as public-facing parts of the site.
Question 9: What information can 'nbtscan' retrieve from a Windows host on a local network?
- Active directory user list
- NetBIOS names, MAC addresses, and workgroup/domain names (Correct answer)
- Open TCP ports and service banners
- Installed software versions
Correct answer: NetBIOS names, MAC addresses, and workgroup/domain names
nbtscan sends NetBIOS Name Service queries to retrieve computer names, logged-in users, and workgroup/domain membership.
Question 10: What tool is commonly used to capture network packets on a Linux system from the command line?
- netstat
- tcpdump (Correct answer)
- netcat
- nmap
Correct answer: tcpdump
tcpdump is a command-line packet analyzer used on Linux to capture and display network traffic.
Question 11: Which HTTP response code confirms that a directory or file found during web enumeration actually exists on the server?
- 403 Forbidden
- 301 Moved Permanently
- 404 Not Found
- 200 OK (Correct answer)
Correct answer: 200 OK
A 200 OK response means the server successfully located and returned the requested resource, confirming its existence.
Question 12: What type of SQL injection does NOT require the application to display query results back to the attacker?
- UNION-based injection
- Blind SQL injection (Correct answer)
- In-band injection
- Error-based injection
Correct answer: Blind SQL injection
Blind SQL injection infers data through true/false conditions or time delays without visible output from the database.
Question 13: Which Nmap script category is used to run scripts that check for known vulnerabilities?
- discovery
- vuln (Correct answer)
- exploit
- safe
Correct answer: vuln
The 'vuln' NSE category runs scripts that check for specific known vulnerabilities on target services.
Question 14: Which of the following Nmap commands would be used to perform a fast scan of the 100 most common ports on a target, discover service versions, and run default scripts, while treating the host as online and skipping the host discovery phase?
- nmap -Pn -F -sV -sC 192.168.1.100 (Correct answer)
- nmap -sS -A -T4 192.168.1.100
- nmap -O --top-ports 20 192.168.1.100
- nmap -sn -p- 192.168.1.100
Correct answer: nmap -Pn -F -sV -sC 192.168.1.100
The command `nmap -Pn -F -sV -sC 192.168.1.100` breaks down as follows: `-Pn` skips host discovery and assumes the host is online. `-F` specifies a fast scan, which covers the 100 most common ports. `-sV` enables service version detection. `-sC` runs the default set of Nmap scripts. This combination precisely meets all the requirements of the scenario.
Question 15: While auditing a network, you identify a device responding on UDP port 161. You suspect it might be running the Simple Network Management Protocol (SNMP) with a default community string. Which of the following actions would be the most effective next step to confirm this and enumerate information?
- Use a tool like `snmp-check` or `onesixtyone` with a list of common community strings. (Correct answer)
- Attempt to connect to the port using Netcat to grab the banner.
- Perform a full UDP port scan on the host using `nmap -sU <IP>`.
- Run an Nmap TCP scan using `nmap -sT -p 161 <IP>`.
Correct answer: Use a tool like `snmp-check` or `onesixtyone` with a list of common community strings.
Tools like `snmp-check` and `onesixtyone` are specifically designed to query SNMP services. They can be used with a wordlist of common community strings (like 'public' and 'private') to test for access and, if successful, automatically dump a large amount of system and network information. This is far more effective than just confirming the port is open.
Question 16: What is a 'false positive' in the context of vulnerability scanning?
- A result that incorrectly identifies a vulnerability that does not actually exist (Correct answer)
- A real vulnerability that was missed by the scanner
- A successfully exploited system
- A verified critical finding
Correct answer: A result that incorrectly identifies a vulnerability that does not actually exist
A false positive is when a scanner reports a vulnerability that does not actually exist, requiring manual verification to confirm findings.
Question 17: A penetration tester is in the initial phase of an assessment and wants to gather information about a target company without directly interacting with its systems. Which of the following approaches is most appropriate?
- Running a port scan with Nmap against the company's web server.
- Querying public WHOIS records and analyzing DNS information. (Correct answer)
- Attempting a zone transfer to enumerate all hosts in their domain.
- Using a vulnerability scanner to probe for weaknesses in their external network.
Correct answer: Querying public WHOIS records and analyzing DNS information.
Querying public WHOIS records and analyzing DNS information are forms of passive reconnaissance. This method relies on publicly available data and does not involve sending packets directly to the target's infrastructure, making it ideal for initial, non-intrusive information gathering. The other options are all forms of active reconnaissance which involve direct interaction.
Question 18: What information does a reverse DNS lookup provide during host discovery?
- The open ports on a remote host
- The hostname associated with a given IP address (Correct answer)
- The geographic location of the IP
- The MAC address of a remote host
Correct answer: The hostname associated with a given IP address
Reverse DNS lookup (PTR query) resolves an IP address back to its associated hostname, revealing useful naming conventions.
Question 19: Which tool is most commonly used in eJPT labs to test connectivity and basic network reachability?
- sqlmap
- hydra
- burpsuite
- ping (Correct answer)
Correct answer: ping
The ping command sends ICMP echo requests to verify that a target host is reachable over the network.
Question 20: Which vulnerability is associated with the CVE-2014-0160 identifier?
- Heartbleed (Correct answer)
- Dirty COW
- EternalBlue
- Shellshock
Correct answer: Heartbleed
CVE-2014-0160, known as Heartbleed, is a critical OpenSSL vulnerability that allows attackers to read memory from affected servers.
Question 21: What is the default port for the HTTPS protocol?
- 80
- 443 (Correct answer)
- 8443
- 8080
Correct answer: 443
HTTPS uses port 443 by default, providing encrypted HTTP communication via TLS/SSL.
Question 22: What is the eJPT exam?
- A course on web designing
- A written exam about the basics of a pen-testing
- A hands-on exam modeled after real-world penetration tests (Correct answer)
- A practical exam about computer programming skills
Correct answer: A hands-on exam modeled after real-world penetration tests
The eJPT exam is renowned for its practical, hands-on approach, distinguishing it from purely theoretical certifications. Candidates are presented with a simulated network environment where they must apply penetration testing methodologies and tools to identify vulnerabilities and compromise targets. This format closely mirrors real-world penetration tests, ensuring practical skill validation.
Question 23: Which Burp Suite feature allows you to send a request to multiple payloads automatically, cycling through a wordlist?
- Burp Comparer
- Burp Repeater
- Burp Intruder (Correct answer)
- Burp Proxy
Correct answer: Burp Intruder
Burp Intruder automates customized attacks by injecting payloads from a wordlist into marked positions within a request.
Question 24: After pivoting into a network via Metasploit routes, which nmap flag should be used to disable ICMP ping discovery so host scanning works through the SOCKS proxy?
- -PE
- -Pn (Correct answer)
- -sP
- -sn
Correct answer: -Pn
The -Pn flag tells nmap to skip host discovery (no ping) and treat all hosts as up, which is necessary when scanning through a SOCKS proxy that can't forward ICMP.
Question 25: After compromising a Linux pivot host, a pentester uses socat to forward connections. Which socat command forwards TCP port 4444 on the pivot to 192.168.1.100:4444?
- socat -L 4444 -R 192.168.1.100:4444
- socat PROXY:4444 192.168.1.100:4444
- socat TCP-LISTEN:4444,fork TCP:192.168.1.100:4444 (Correct answer)
- socat LISTEN:4444 CONNECT:192.168.1.100:4444
Correct answer: socat TCP-LISTEN:4444,fork TCP:192.168.1.100:4444
Socat's TCP-LISTEN with fork creates a listening socket that relays each accepted connection to the specified remote address and port.
Question 26: What does 'OS fingerprinting' help an auditor determine during a host audit?
- The user accounts on the host
- The firewall rules protecting the host
- The operating system and version running on a target host (Correct answer)
- The physical location of the host
Correct answer: The operating system and version running on a target host
OS fingerprinting analyzes network responses to identify the target's operating system and version.
Question 27: A penetration tester is performing OSINT on a target company and wants to gather employee names, email addresses, and subdomains from public sources like search engines. Which tool is best suited for this task?
- Hydra
- theHarvester (Correct answer)
- Gobuster
- Nikto
Correct answer: theHarvester
theHarvester is an OSINT tool designed to gather emails, names, subdomains, IPs, and URLs from various public sources like search engines (Google, Bing) and PGP key servers. It's a staple in the passive information gathering phase of a penetration test. Gobuster is for directory/subdomain brute-forcing, Nikto is a web scanner, and Hydra is a password cracker.
Question 28: When comparing active and passive reconnaissance, which of the following is a primary characteristic of active reconnaissance?
- It relies solely on publicly available information like social media and news articles.
- It has a lower chance of providing accurate, real-time data compared to passive methods.
- It involves direct interaction with the target's systems, creating network traffic that can be logged. (Correct answer)
- It is undetectable by the target organization.
Correct answer: It involves direct interaction with the target's systems, creating network traffic that can be logged.
Active reconnaissance is defined by its direct engagement with the target's infrastructure. Activities like port scanning, banner grabbing, and sending DNS queries directly to the target's servers generate network traffic that can trigger alerts and be logged by security systems. In contrast, passive reconnaissance is stealthier because it uses third-party sources.
Question 29: During a host audit of a Linux machine, you need to find all files that have the Set User ID (SUID) permission bit set, as these could be potential vectors for privilege escalation. Which of the following commands would accomplish this?
- ls -l / -R | grep 'r-s'
- chmod -R u+s /
- find / -perm -u=s -type f 2>/dev/null (Correct answer)
- grep -r "suid" /etc
Correct answer: find / -perm -u=s -type f 2>/dev/null
The command `find / -perm -u=s -type f 2>/dev/null` is the standard and most accurate way to locate SUID files. `find /` starts the search from the root directory. `-perm -u=s` specifies the permission to look for (SUID bit for the user). `-type f` limits the search to files only. `2>/dev/null` redirects any permission-denied errors to null, cleaning up the output.
Question 30: What is the main advantage of bcrypt over MD5 for password storage?
- bcrypt produces longer hashes that take more storage space
- bcrypt is a symmetric cipher while MD5 is a hash function
- bcrypt is intentionally slow and includes a work factor that makes brute-force cracking much harder (Correct answer)
- bcrypt automatically salts hashes while MD5 does not support salting
Correct answer: bcrypt is intentionally slow and includes a work factor that makes brute-force cracking much harder
bcrypt uses a configurable work factor (cost parameter) that makes it computationally expensive to compute, drastically slowing brute-force and dictionary attacks compared to fast hashes like MD5.
Question 31: Which Metasploit module can dump password hashes from a compromised Windows host to facilitate lateral movement?
- exploit/windows/smb/ms17_010_eternalblue
- post/multi/recon/local_exploit_suggester
- auxiliary/scanner/smb/smb_login
- post/windows/gather/hashdump (Correct answer)
Correct answer: post/windows/gather/hashdump
The hashdump post module extracts NTLM password hashes from a Windows host's SAM database, which can then be used for Pass-the-Hash attacks.
Question 32: Which hash type would you specify with '-m 22000' in Hashcat?
- NTLM
- bcrypt
- SHA-512crypt
- WPA2-PBKDF2-PMKID+EAPOL (Correct answer)
Correct answer: WPA2-PBKDF2-PMKID+EAPOL
Hashcat mode 22000 targets WPA2 (PBKDF2-HMAC-SHA1) hashes in the modern hcwpax format, used to crack captured Wi-Fi handshakes.
Question 33: A pentester compromises a dual-homed Linux host at 10.0.0.5 (eth0) and 172.16.0.5 (eth1). To scan the 172.16.0.0/24 network from their Kali machine, they set up a SOCKS5 proxy and prepend 'proxychains' before which tool?
- Metasploit's db_nmap
- Burp Suite
- nmap (Correct answer)
- Wireshark
Correct answer: nmap
Proxychains can wrap nmap so that TCP scans are routed through the SOCKS proxy to reach otherwise unreachable internal segments.
Question 34: Within Burp Suite, which tool is primarily used to act as a man-in-the-middle, allowing a tester to intercept, view, and modify all HTTP/S requests and responses between their browser and the target application in real-time?
- Decoder
- Repeater
- Intruder
- Proxy (Correct answer)
Correct answer: Proxy
The Burp Proxy tool is the core of Burp Suite and functions as an intercepting web proxy. It allows the user to intercept and modify traffic passing in both directions between the browser and the target server. Intruder is for automated attacks, Repeater is for manually re-sending and modifying individual requests, and Decoder is for data encoding/decoding.
Question 35: Which Meterpreter command captures a screenshot of the target's desktop?
- snap
- capture
- screenshot (Correct answer)
- screengrab
Correct answer: screenshot
The 'screenshot' command in Meterpreter takes a snapshot of the target's current desktop.
Question 36: Which tool is commonly used to capture and analyze network packets during a host audit?
- Metasploit
- Hydra
- Wireshark (Correct answer)
- Nikto
Correct answer: Wireshark
Wireshark is a network protocol analyzer used to capture and inspect live or recorded network traffic.
eJPT (eLearnSecurity Junior Penetration Tester)
The eJPT certification by INE Security validates entry-level penetration testing skills including information gathering, scanning, exploitation, and web application security in a hands-on lab environment.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds