Network Protocols and Traffic Analysis Flashcards
6 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Network Protocols and Traffic Analysis flashcards as text
Which port is used by default for the SMB protocol?
Answer: 139/445
SMB (Server Message Block) uses ports 139 and 445 for file sharing and Windows network services.
What tool is commonly used to capture network packets on a Linux system from the command line?
Answer: tcpdump
tcpdump is a command-line packet analyzer used on Linux to capture and display network traffic.
Which protocol does DNS use by default for standard queries on port 53?
Answer: UDP
DNS uses UDP on port 53 for standard queries because it is faster and lower overhead for small request/response packets.
In Wireshark, what does the 'follow TCP stream' feature allow an analyst to do?
Answer: Reassemble and view the full conversation between two hosts
Follow TCP stream reassembles all packets in a TCP session, displaying the full readable conversation between two endpoints.
Which network layer is responsible for breaking data into frames and MAC addressing?
Answer: Data Link Layer (Layer 2)
The Data Link Layer (Layer 2) handles framing data for transmission and uses MAC addresses for local network delivery.
What type of attack involves poisoning ARP tables to redirect traffic through an attacker's machine?
Answer: ARP Poisoning / Man-in-the-Middle
ARP poisoning sends forged ARP replies to corrupt the ARP cache of hosts, enabling man-in-the-middle traffic interception.