Host and Network Auditing Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Host and Network Auditing flashcards as text
What does ARP scanning reveal during a network audit that ICMP ping sweeps may miss?
Answer: Hosts that block ICMP but respond to ARP requests on the local subnet
ARP works at Layer 2 and always gets responses from live hosts on the same subnet, even if they block ICMP.
Which tool is specifically designed for banner grabbing to identify service versions?
Answer: Netcat (nc)
Netcat can connect to open ports and read the service banner, revealing version information without authentication.
During a host audit, you find TCP port 25 open. Which service should you investigate?
Answer: SMTP (Simple Mail Transfer Protocol)
TCP port 25 is the default port for SMTP, used for sending email between mail servers.
What is the difference between a vulnerability scan and a penetration test?
Answer: A vulnerability scan identifies weaknesses without exploiting them; a pentest actively exploits vulnerabilities
Vulnerability scanning identifies and reports potential weaknesses, while penetration testing goes further by attempting to exploit them.
Which command would you use with Nmap to run all default NSE scripts against a target?
Answer: nmap -sC
The -sC flag runs Nmap's default NSE (Nmap Scripting Engine) scripts against the target.
What information does a reverse DNS lookup provide during host discovery?
Answer: The hostname associated with a given IP address
Reverse DNS lookup (PTR query) resolves an IP address back to its associated hostname, revealing useful naming conventions.
Which Nmap scan type is used to scan UDP ports on a target?
Answer: -sU
The -sU flag performs a UDP scan, which is important since many services like DNS, SNMP, and DHCP run on UDP.