Trivia Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Trivia flashcards as text
Which Nmap script category is used to run scripts that check for known vulnerabilities?
Answer: vuln
The 'vuln' NSE category runs scripts that check for specific known vulnerabilities on target services.
What is the default port for HTTPS (HTTP Secure) traffic?
Answer: 443
HTTPS uses TCP port 443 by default, encrypting HTTP traffic with TLS/SSL.
In the context of eJPT, what does 'pivoting' mean during a penetration test?
Answer: Using a compromised host to attack other internal systems
Pivoting uses a compromised machine as a relay to reach and attack systems in otherwise inaccessible network segments.
Which file on a Windows system contains the local user account password hashes?
Answer: SAM
The SAM (Security Account Manager) database stores local user password hashes on Windows systems.
What is the purpose of running 'whoami' after gaining a shell during a penetration test?
Answer: Identify the current user context and privileges
The 'whoami' command reveals the current user account running the shell, helping assess privilege level.
Which HTTP method is most commonly associated with submitting form data that could be vulnerable to SQL injection?
Answer: POST
POST requests commonly carry form data in the request body, which is a frequent injection point for SQL attacks.
What does 'TTL' stand for in the context of network packets?
Answer: Time To Live
TTL (Time To Live) is a field in IP packets that limits their lifespan by decrementing at each router hop.