Network Scanning and Enumeration Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Network Scanning and Enumeration flashcards as text
Which tool is used to perform DNS zone transfer attacks during OSCP reconnaissance?
Answer: dig axfr
The command 'dig axfr @ ' requests a full DNS zone transfer, which can reveal all DNS records if the server is misconfigured.
During an OSCP lab, you find port 111 open on a Linux target. What service is most likely running?
Answer: Portmapper/RPC
Port 111 is used by the Portmapper (rpcbind) service, which maps RPC program numbers to network port numbers and is commonly found on Linux/Unix systems.
What is the purpose of the 'rpcinfo -p ' command during enumeration?
Answer: Enumerate all RPC services and their port numbers on the target
The 'rpcinfo -p' command queries the portmapper and lists all registered RPC programs, their versions, protocol, and the ports they are listening on.
Which Nmap timing template (-T) value provides the most aggressive scan speed?
Answer: -T5
The -T5 'insane' timing template is the most aggressive, sending packets as fast as possible at the risk of missing results due to network congestion.
What tool would you use to brute-force directory and file names on a web server during OSCP?
Answer: gobuster
Gobuster is a tool used to brute-force URIs (directories and files), DNS subdomains, and virtual host names using wordlists.
When enumerating NFS shares during OSCP, which command shows available exports on a target?
Answer: showmount -e
The 'showmount -e' command queries the NFS server and displays its list of exported directories along with any access restrictions.