โ† All OSCP Flashcard Decks

Network Scanning and Enumeration Flashcards

6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Network Scanning and Enumeration flashcards as text
  1. Which Nmap scan type sends TCP SYN packets and is often called a 'half-open' scan?

    Answer: -sS (SYN scan)

    The -sS SYN scan sends a SYN packet and listens for a SYN-ACK without completing the three-way handshake, making it stealthier than a full connect scan.

  2. What Nmap script category is most useful for initial service version detection during OSCP enumeration?

    Answer: --script=default

    The 'default' script category runs commonly useful scripts that are safe, reliable, and provide helpful service information without being intrusive.

  3. Which Nmap flag combination is commonly recommended for a comprehensive initial OSCP scan?

    Answer: -sV -sC -p- -T4

    The combination -sV -sC -p- -T4 scans all 65535 ports with service version detection and default scripts at an aggressive timing template.

  4. What tool is best suited for enumerating SMB shares on a Windows target during an OSCP engagement?

    Answer: enum4linux

    Enum4linux is a tool for enumerating information from Windows and Samba systems, including shares, users, groups, and password policies.

  5. Which command would you use with Nmap to enumerate SNMP services running on UDP port 161?

    Answer: nmap -sU -p 161 --script=snmp-info

    SNMP runs on UDP port 161, so you must use -sU for a UDP scan combined with the snmp-info script to enumerate SNMP information.

  6. What does the Nmap -A flag enable?

    Answer: OS detection, version detection, script scanning, and traceroute

    The -A flag enables aggressive mode, which combines OS detection (-O), version scanning (-sV), script scanning (-sC), and traceroute in a single flag.