โ† All EJPT Flashcard Decks

Scanning and Enumeration Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Scanning and Enumeration flashcards as text
  1. Which Nmap flag enables the use of decoy addresses to obscure the true source of a scan?

    Answer: -D

    The '-D ' option makes the scan appear to originate from multiple IP addresses, hiding the real source.

  2. When enumerating a web application, what does directory brute-forcing with Gobuster primarily accomplish?

    Answer: Discovers hidden or unlisted directories and files on a web server

    Gobuster systematically requests paths from a wordlist to find directories and files the server doesn't publicly link to.

  3. What is the significance of TCP port 3389 discovered open on a target?

    Answer: Windows Remote Desktop Protocol (RDP)

    Port 3389 is the default port for Microsoft's Remote Desktop Protocol (RDP), allowing GUI-based remote access to Windows hosts.

  4. Which scanning technique is used to bypass simple stateless firewalls by sending a TCP packet with only the FIN flag set?

    Answer: FIN scan

    A FIN scan sends packets with only the FIN flag, which some stateless firewalls pass because they don't match a SYN rule, while closed ports respond with RST.

  5. What information can 'nbtscan' retrieve from a Windows host on a local network?

    Answer: NetBIOS names, MAC addresses, and workgroup/domain names

    nbtscan sends NetBIOS Name Service queries to retrieve computer names, logged-in users, and workgroup/domain membership.

  6. During a pentest, you discover port 25 open on a target server. Which protocol and service does this indicate?

    Answer: SMTP email service

    TCP port 25 is the default port for SMTP (Simple Mail Transfer Protocol), used to send and relay email messages.

  7. Which Nmap timing template balances speed and accuracy and is recommended for most standard penetration tests?

    Answer: -T4 (Aggressive)

    '-T4' (Aggressive) speeds up scans significantly while remaining reliable, making it the most commonly recommended template for authorized pentests.