โ† All EJPT Flashcard Decks

Scanning and Enumeration Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Scanning and Enumeration flashcards as text
  1. What does the Nmap '--script=vuln' option do during a scan?

    Answer: Runs NSE scripts in the 'vuln' category to check for known vulnerabilities

    The 'vuln' NSE category contains scripts that probe services for specific known vulnerabilities without exploiting them.

  2. Which tool can be used to enumerate valid usernames on a Linux system by exploiting the 'finger' service (port 79)?

    Answer: finger (native command)

    The native 'finger' command queries the finger daemon to retrieve user information including login name, full name, and idle time.

  3. During an eJPT exam scenario, you want to find all hosts with port 80 open in the 10.10.10.0/24 subnet quickly. Which Nmap command is best?

    Answer: nmap -p 80 --open 10.10.10.0/24

    '-p 80 --open' restricts the scan to port 80 and only displays hosts where it's open, making results fast and clean.

  4. What is the primary purpose of running 'rpcclient -U "" -N ' during Windows enumeration?

    Answer: Connect anonymously to the RPC service to enumerate users and shares

    rpcclient with an empty username and -N (no password) attempts a null session to enumerate domain users, shares, and groups via MS-RPC.

  5. Which HTTP response code confirms that a directory or file found during web enumeration actually exists on the server?

    Answer: 200 OK

    A 200 OK response means the server successfully located and returned the requested resource, confirming its existence.

  6. In the context of eJPT scanning, what is 'banner grabbing' used for?

    Answer: Capturing service banners to identify software name and version

    Banner grabbing reads the text a service sends upon connection, often revealing the application name, version, and sometimes OS details.

  7. Which command using Nmap's NSE would specifically check if an SMB target is vulnerable to EternalBlue (MS17-010)?

    Answer: nmap --script=smb-vuln-ms17-010

    The 'smb-vuln-ms17-010' NSE script probes SMB to determine if the host is missing the MS17-010 patch and is vulnerable to EternalBlue.