โ† All EJPT Flashcard Decks

Scanning and Enumeration Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Scanning and Enumeration flashcards as text
  1. Which Nmap scan type sends a SYN packet and waits for a SYN-ACK without completing the three-way handshake?

    Answer: SYN stealth scan (-sS)

    SYN stealth scan (-sS) sends a SYN and tears down the connection after receiving SYN-ACK, never completing the handshake.

  2. What does the Nmap option '-p-' specify?

    Answer: Scan all 65535 TCP ports

    The '-p-' flag tells Nmap to scan all 65535 TCP ports instead of just the default top 1000.

  3. Which SMB enumeration tool can list shares, users, and OS information on a target Windows host?

    Answer: enum4linux

    enum4linux is a Linux tool that wraps Samba utilities to enumerate SMB shares, users, groups, and OS details.

  4. What is the purpose of the Nmap '-sV' flag?

    Answer: Detect service versions on open ports

    '-sV' probes open ports to determine the service name and version number running on each.

  5. During an Nmap scan, a port returns the state 'filtered'. What does this most likely indicate?

    Answer: A firewall or ACL is blocking probe packets

    A 'filtered' state means Nmap cannot determine if the port is open because a packet filter is dropping or blocking probes.

  6. Which protocol does DNS primarily use for standard queries, and on which port?

    Answer: UDP port 53

    DNS uses UDP port 53 for standard queries, switching to TCP port 53 only for zone transfers or responses exceeding 512 bytes.

  7. What Nmap scripting engine (NSE) category is most useful for enumerating additional details from discovered services during a pentest?

    Answer: discovery

    The 'discovery' NSE category contains scripts that actively enumerate services, retrieve banners, and gather additional host information.