Network Scanning and Enumeration Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Network Scanning and Enumeration flashcards as text
Which Nmap output format is most useful for importing results into other tools during OSCP?
Answer: -oX (XML)
The -oX XML output format is the most versatile for importing into tools like Metasploit, OpenVAS, and other security platforms that parse XML.
What does the acronym 'OSINT' stand for in the context of OSCP reconnaissance?
Answer: Open Source Intelligence
OSINT (Open Source Intelligence) refers to collecting information from publicly available sources like websites, social media, WHOIS records, and DNS data.
Which service typically runs on port 3306 and is a common target for enumeration in OSCP labs?
Answer: MySQL/MariaDB
Port 3306 is the default port for MySQL and MariaDB database servers, which are frequently found in OSCP lab environments.
What Nmap script can identify anonymous FTP login on a target?
Answer: --script=ftp-anon
The ftp-anon script checks if an FTP server allows anonymous logins, which can be a significant misconfiguration exposing files without authentication.
Which protocol and port combination indicates an LDAP service that might be enumerated for Active Directory information?
Answer: TCP 389
LDAP (Lightweight Directory Access Protocol) runs on TCP port 389 and is used by Active Directory for directory queries, making it a valuable enumeration target.
What tool provides an automated network and service enumeration report, similar to running multiple tools in sequence?
Answer: AutoRecon
AutoRecon is a multi-threaded network reconnaissance tool that automatically runs multiple scanning tools and organizes results into a structured directory.