Trivia Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Trivia flashcards as text
Which tool is commonly used in eJPT labs to perform dictionary-based password attacks against web login forms?
Answer: Hydra
Hydra is a fast network login cracker that supports brute-forcing HTTP form logins and many other protocols.
What is the purpose of the 'LHOST' parameter when configuring a Metasploit reverse shell payload?
Answer: The listening IP address of the attacker's machine
LHOST specifies the attacker's IP address that the reverse shell will connect back to after execution.
Which command-line tool can be used to transfer files on Linux using HTTP, FTP, or other protocols?
Answer: wget
wget is a non-interactive download utility that retrieves files from web and FTP servers via command line.
In penetration testing methodology, what phase comes directly after reconnaissance?
Answer: Scanning and Enumeration
After reconnaissance, the scanning and enumeration phase identifies open ports, services, and vulnerabilities on targets.
What type of SQL injection does NOT require the application to display query results back to the attacker?
Answer: Blind SQL injection
Blind SQL injection infers data through true/false conditions or time delays without visible output from the database.
Which Wireshark filter would display only HTTP traffic?
Answer: http
The 'http' display filter in Wireshark shows all packets using the HTTP application protocol.
What is the eJPT certification issued by?
Answer: eLearnSecurity (now INE Security)
The eJPT is issued by eLearnSecurity, which is now part of INE Security, as an entry-level pentesting certification.