← All OSCP Flashcard Decks

Network Scanning and Enumeration Flashcards

6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Network Scanning and Enumeration flashcards as text
  1. Which tool is used to perform DNS zone transfer attacks during OSCP reconnaissance?

    Answer: dig axfr

    The command 'dig axfr @ ' requests a full DNS zone transfer, which can reveal all DNS records if the server is misconfigured.

  2. During an OSCP lab, you find port 111 open on a Linux target. What service is most likely running?

    Answer: Portmapper/RPC

    Port 111 is used by the Portmapper (rpcbind) service, which maps RPC program numbers to network port numbers and is commonly found on Linux/Unix systems.

  3. What is the purpose of the 'rpcinfo -p ' command during enumeration?

    Answer: Enumerate all RPC services and their port numbers on the target

    The 'rpcinfo -p' command queries the portmapper and lists all registered RPC programs, their versions, protocol, and the ports they are listening on.

  4. Which Nmap timing template (-T) value provides the most aggressive scan speed?

    Answer: -T5

    The -T5 'insane' timing template is the most aggressive, sending packets as fast as possible at the risk of missing results due to network congestion.

  5. What tool would you use to brute-force directory and file names on a web server during OSCP?

    Answer: gobuster

    Gobuster is a tool used to brute-force URIs (directories and files), DNS subdomains, and virtual host names using wordlists.

  6. When enumerating NFS shares during OSCP, which command shows available exports on a target?

    Answer: showmount -e

    The 'showmount -e' command queries the NFS server and displays its list of exported directories along with any access restrictions.