โ† All EJPT Flashcard Decks

Host and Network Auditing Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Host and Network Auditing flashcards as text
  1. Which Nmap script is used to enumerate SMB shares on a Windows host?

    Answer: smb-enum-shares

    The smb-enum-shares NSE script lists available SMB shares on a target Windows system.

  2. What does the Nmap flag '-sV' accomplish during a scan?

    Answer: Version detection of running services

    -sV probes open ports to determine service/version information running on the target.

  3. During a network audit, you discover a host responding on TCP 445. Which protocol is most likely running?

    Answer: SMB (Server Message Block)

    TCP port 445 is the standard port for SMB, used for Windows file and printer sharing.

  4. Which tool is commonly used to capture and analyze network packets during a host audit?

    Answer: Wireshark

    Wireshark is a network protocol analyzer used to capture and inspect live or recorded network traffic.

  5. What Nmap command would scan all 65535 TCP ports on a target?

    Answer: nmap -p-

    The -p- flag tells Nmap to scan all 65535 TCP ports instead of just the default top 1000.

  6. Which command-line tool on Linux can be used to display active network connections and listening ports?

    Answer: netstat -an

    netstat -an displays all active connections and listening ports in numeric format.

  7. In host auditing, what does the term 'attack surface' refer to?

    Answer: The sum of all exposed services, ports, and interfaces that could be exploited

    The attack surface encompasses all points where an attacker can try to enter or extract data from a system.