โ† All EJPT Flashcard Decks

Scanning and Enumeration Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Scanning and Enumeration flashcards as text
  1. Which command performs a DNS zone transfer against the domain example.com using the dig utility?

    Answer: dig axfr example.com @ns1.example.com

    The 'axfr' query type requests a full zone transfer from the specified nameserver, replicating all DNS records.

  2. What is the default port for SNMP?

    Answer: UDP 161

    SNMP agents listen on UDP port 161 for queries; UDP 162 is used for SNMP trap messages.

  3. Which Nmap option outputs scan results in all formats simultaneously (normal, XML, and grepable)?

    Answer: -oA

    '-oA ' saves results in all three formats: .nmap (normal), .xml, and .gnmap (grepable).

  4. During enumeration you run 'netdiscover -r 192.168.1.0/24'. What is this tool primarily used for?

    Answer: ARP-based host discovery on a local network

    netdiscover uses ARP requests to discover live hosts on a local subnet, making it effective for internal network reconnaissance.

  5. Which SNMP community string is typically configured by default on many network devices?

    Answer: public

    The default read-only SNMP community string on most devices is 'public', which should be changed during hardening.

  6. What does the acronym 'OS fingerprinting' refer to in the context of Nmap scanning?

    Answer: Identifying the operating system of a target host based on network responses

    OS fingerprinting analyzes TCP/IP stack behavior and packet characteristics to determine the target's operating system.

  7. Which tool is commonly used to enumerate NFS shares on a target host?

    Answer: showmount

    The 'showmount -e ' command queries the NFS server's mount daemon to list exported (shared) directories.