Network Protocols and Traffic Analysis Flashcards
6 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Network Protocols and Traffic Analysis flashcards as text
Which command displays active network connections and listening ports on a Windows or Linux system?
Answer: netstat -an
netstat -an shows all active connections and listening ports in numeric format on both Windows and Linux.
What is the purpose of a subnet mask in networking?
Answer: Identify the network and host portions of an IP address
A subnet mask distinguishes the network portion from the host portion of an IP address to define network boundaries.
During traffic analysis, what does a large number of SYN packets without corresponding SYN-ACK responses typically indicate?
Answer: A SYN flood denial-of-service attack
A flood of unanswered SYN packets is a classic indicator of a SYN flood DoS attack intended to exhaust server resources.
Which protocol is responsible for translating domain names to IP addresses?
Answer: DNS
DNS (Domain Name System) resolves human-readable domain names like example.com into IP addresses.
What is the default port for the HTTPS protocol?
Answer: 443
HTTPS uses port 443 by default, providing encrypted HTTP communication via TLS/SSL.
When capturing traffic on an eJPT lab, which interface would typically be used to monitor traffic between the attacker and a target on the same subnet?
Answer: eth0 or the LAN-facing interface
eth0 or the LAN-facing NIC is used to capture traffic between hosts on the same subnet in a typical lab environment.