โ† All EJPT Flashcard Decks

Host and Network Auditing Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Host and Network Auditing flashcards as text
  1. What is the purpose of running 'nmap -O' against a target?

    Answer: Operating system detection

    The -O flag enables OS detection, using TCP/IP fingerprinting to guess the target's operating system.

  2. Which Nmap output format is most useful for importing results into other tools for further processing?

    Answer: XML (-oX)

    XML output (-oX) is machine-readable and supported by many tools like Metasploit for importing scan data.

  3. During a network audit, a host at 192.168.1.50 has TCP 3389 open. What service is likely running?

    Answer: Remote Desktop Protocol (RDP)

    TCP port 3389 is the default port for Microsoft's Remote Desktop Protocol (RDP).

  4. What does 'OS fingerprinting' help an auditor determine during a host audit?

    Answer: The operating system and version running on a target host

    OS fingerprinting analyzes network responses to identify the target's operating system and version.

  5. Which protocol uses port 161 UDP and is commonly audited for information disclosure?

    Answer: SNMP (Simple Network Management Protocol)

    SNMP on UDP 161 can expose system information, running processes, and network configuration if misconfigured.

  6. What is the main purpose of a network topology map during an audit?

    Answer: To visualize the relationships and connections between hosts in the network

    A network topology map shows how hosts interconnect, helping auditors understand the network architecture and attack paths.

  7. Which Nmap timing template provides the fastest scan while risking detection or inaccuracy?

    Answer: -T5 (Insane)

    -T5 is the fastest Nmap timing template but may overwhelm targets, drop packets, or trigger IDS alerts.