Host and Network Auditing Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Host and Network Auditing flashcards as text
What is the purpose of running 'nmap -O' against a target?
Answer: Operating system detection
The -O flag enables OS detection, using TCP/IP fingerprinting to guess the target's operating system.
Which Nmap output format is most useful for importing results into other tools for further processing?
Answer: XML (-oX)
XML output (-oX) is machine-readable and supported by many tools like Metasploit for importing scan data.
During a network audit, a host at 192.168.1.50 has TCP 3389 open. What service is likely running?
Answer: Remote Desktop Protocol (RDP)
TCP port 3389 is the default port for Microsoft's Remote Desktop Protocol (RDP).
What does 'OS fingerprinting' help an auditor determine during a host audit?
Answer: The operating system and version running on a target host
OS fingerprinting analyzes network responses to identify the target's operating system and version.
Which protocol uses port 161 UDP and is commonly audited for information disclosure?
Answer: SNMP (Simple Network Management Protocol)
SNMP on UDP 161 can expose system information, running processes, and network configuration if misconfigured.
What is the main purpose of a network topology map during an audit?
Answer: To visualize the relationships and connections between hosts in the network
A network topology map shows how hosts interconnect, helping auditors understand the network architecture and attack paths.
Which Nmap timing template provides the fastest scan while risking detection or inaccuracy?
Answer: -T5 (Insane)
-T5 is the fastest Nmap timing template but may overwhelm targets, drop packets, or trigger IDS alerts.