← All EJPT Flashcard Decks

Network Protocols and Traffic Analysis Flashcards

6 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Network Protocols and Traffic Analysis flashcards as text
  1. Which command displays active network connections and listening ports on a Windows or Linux system?

    Answer: netstat -an

    netstat -an shows all active connections and listening ports in numeric format on both Windows and Linux.

  2. What is the purpose of a subnet mask in networking?

    Answer: Identify the network and host portions of an IP address

    A subnet mask distinguishes the network portion from the host portion of an IP address to define network boundaries.

  3. During traffic analysis, what does a large number of SYN packets without corresponding SYN-ACK responses typically indicate?

    Answer: A SYN flood denial-of-service attack

    A flood of unanswered SYN packets is a classic indicator of a SYN flood DoS attack intended to exhaust server resources.

  4. Which protocol is responsible for translating domain names to IP addresses?

    Answer: DNS

    DNS (Domain Name System) resolves human-readable domain names like example.com into IP addresses.

  5. What is the default port for the HTTPS protocol?

    Answer: 443

    HTTPS uses port 443 by default, providing encrypted HTTP communication via TLS/SSL.

  6. When capturing traffic on an eJPT lab, which interface would typically be used to monitor traffic between the attacker and a target on the same subnet?

    Answer: eth0 or the LAN-facing interface

    eth0 or the LAN-facing NIC is used to capture traffic between hosts on the same subnet in a typical lab environment.