Scanning and Enumeration Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Scanning and Enumeration flashcards as text
Which command performs a DNS zone transfer against the domain example.com using the dig utility?
Answer: dig axfr example.com @ns1.example.com
The 'axfr' query type requests a full zone transfer from the specified nameserver, replicating all DNS records.
What is the default port for SNMP?
Answer: UDP 161
SNMP agents listen on UDP port 161 for queries; UDP 162 is used for SNMP trap messages.
Which Nmap option outputs scan results in all formats simultaneously (normal, XML, and grepable)?
Answer: -oA
'-oA ' saves results in all three formats: .nmap (normal), .xml, and .gnmap (grepable).
During enumeration you run 'netdiscover -r 192.168.1.0/24'. What is this tool primarily used for?
Answer: ARP-based host discovery on a local network
netdiscover uses ARP requests to discover live hosts on a local subnet, making it effective for internal network reconnaissance.
Which SNMP community string is typically configured by default on many network devices?
Answer: public
The default read-only SNMP community string on most devices is 'public', which should be changed during hardening.
What does the acronym 'OS fingerprinting' refer to in the context of Nmap scanning?
Answer: Identifying the operating system of a target host based on network responses
OS fingerprinting analyzes TCP/IP stack behavior and packet characteristics to determine the target's operating system.
Which tool is commonly used to enumerate NFS shares on a target host?
Answer: showmount
The 'showmount -e ' command queries the NFS server's mount daemon to list exported (shared) directories.