Mixed Deck — All EJPT Topics Flashcards
100 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All EJPT Topics flashcards as text
Which port is associated with the HTTPS service during a web server audit?
Answer: 443
TCP port 443 is the standard port for HTTPS (HTTP over TLS/SSL) encrypted web traffic.
During a network audit, a junior penetration tester captures network traffic using Wireshark. They apply the display filter `http.request.method == "POST"`. What is the primary purpose of using this specific filter?
Answer: To identify potential login attempts or data submissions over HTTP.
The `http.request.method == "POST"` filter in Wireshark specifically isolates HTTP requests that use the POST method. This method is commonly used to send data from a client to a server, such as submitting login credentials, filling out forms, or uploading files. Analyzing this traffic is crucial for finding sensitive information being transmitted in cleartext.
What is the purpose of the CVSS score in penetration testing reports?
Answer: To standardize the severity rating of vulnerabilities on a numeric scale
CVSS (Common Vulnerability Scoring System) provides a standardized 0–10 numeric score reflecting the severity of a vulnerability.
Which Nmap script category is most useful for detecting known vulnerabilities during a vulnerability assessment?
Answer: vuln
The 'vuln' script category contains NSE scripts specifically designed to check for known vulnerabilities in services.
Which post-exploitation Meterpreter command is used to attempt privilege escalation on a Windows target?
Answer: getsystem
'getsystem' attempts multiple techniques to elevate Meterpreter's privileges to SYSTEM level on a Windows host.
What is a 'hidden SSID' and how is it most reliably uncovered during a wireless penetration test?
Answer: An SSID omitted from beacon frames; uncovered by capturing probe responses when clients reconnect
Hidden SSIDs suppress the network name in beacon frames, but the SSID is revealed in probe request/response frames when clients attempt to reconnect.
Which Hashcat attack mode uses a wordlist combined with rules to generate password candidates?
Answer: Wordlist mode with rules (-a 0 -r)
Hashcat's straight/wordlist mode (-a 0) paired with a rules file (-r) applies transformations like capitalization and substitutions to each word in the list.
You have gained a low-privilege shell on a Linux server. To plan your next steps for privilege escalation, you need to determine the exact kernel version and operating system details. Which of the following commands would provide this essential information?
Answer: uname -a
The `uname -a` command prints all available system information, including the kernel name, hostname, kernel release version, machine hardware name, and operating system. This is a crucial first step in searching for kernel-based privilege escalation exploits.
A penetration tester has gained a shell on a public-facing web server (10.0.0.5). During internal reconnaissance, they discover an internal network segment (192.168.1.0/24) connected to the server's second network interface. To scan this internal network from their attack machine, which technique must they employ?
Answer: Pivoting
Pivoting is the technique of using a compromised host to route traffic from the attacker's machine to an otherwise inaccessible internal network. This allows the attacker to "pivot" their attack through the compromised machine to reach other systems.
What is the purpose of the Metasploit 'db_nmap' command?
Answer: Run Nmap scans and automatically import results into the Metasploit database
The 'db_nmap' command runs Nmap from within Metasploit and automatically stores the scan results in the Metasploit PostgreSQL database for later use.
What does 'patch management' aim to accomplish in the context of vulnerability remediation?
Answer: Apply vendor-released fixes to close known vulnerabilities in software
Patch management is the process of systematically applying software updates and security patches to fix known vulnerabilities identified during assessments.
In a TCP three-way handshake, what is the correct sequence of flags?
Answer: SYN, SYN-ACK, ACK
The TCP three-way handshake uses SYN from client, SYN-ACK from server, and ACK from client to establish a connection.
What does the term 'attack surface' refer to in penetration testing?
Answer: All possible entry points an attacker could use to compromise a system
The attack surface encompasses all exposed points — open ports, services, interfaces, and input vectors — that an attacker could exploit.
During enumeration you run 'netdiscover -r 192.168.1.0/24'. What is this tool primarily used for?
Answer: ARP-based host discovery on a local network
netdiscover uses ARP requests to discover live hosts on a local subnet, making it effective for internal network reconnaissance.
What is the goal of the eJPT labs?
Answer: To follow the penetration testing process in its entirety and discover as many vulnerabilities as possible
The eJPT labs are designed to simulate a comprehensive penetration testing engagement, not just to achieve a single objective like "popping shells." The goal is to guide students through the entire penetration testing process, from reconnaissance and vulnerability analysis to exploitation and post-exploitation, encouraging them to identify and document all discovered vulnerabilities. This holistic approach prepares individuals for real-world scenarios where a thorough assessment is paramount.
During an eJPT exam scenario, you want to find all hosts with port 80 open in the 10.10.10.0/24 subnet quickly. Which Nmap command is best?
Answer: nmap -p 80 --open 10.10.10.0/24
'-p 80 --open' restricts the scan to port 80 and only displays hosts where it's open, making results fast and clean.
Which of the following Metasploit module types is specifically designed to perform actions such as gathering evidence, escalating privileges, or pivoting on a target system *after* an initial exploit has already succeeded and a session has been established?
Answer: post
Post-exploitation (post) modules are used after a system has been successfully compromised. They are not used for the initial exploit but for subsequent actions like data exfiltration, maintaining access, and lateral movement within the network.
What does ARP stand for in networking?
Answer: Address Resolution Protocol
ARP stands for Address Resolution Protocol and maps IP addresses to MAC addresses on a local network.
What is the name given to the most challenging labs in the course?
Answer: black-box labs
In the eJPT course, "black-box labs" are designated as the most challenging. This term signifies that candidates are given no prior information about the target system's internal structure, network topology, or vulnerabilities. This approach simulates real-world penetration tests where testers must discover everything from scratch, relying solely on external reconnaissance and active scanning techniques.
When using OpenVAS (Greenbone), what is the first step before running a vulnerability scan?
Answer: Create a target and select a scan configuration
In OpenVAS/Greenbone, you must first define a target (IP/host) and choose a scan configuration before initiating any vulnerability scan.