Lecture 5 Flashcards

1
Q

What is the purpose of enumeration tools?

A

To discover assets and manage vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define Enumeration.

A

Scanning the network & hosts to map out the attack surface.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the two main methods of enumeration?

A
  • Active
  • Passive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What types of reconnaissance tools are used in mapping?

A
  • Open-source Intelligence (OSINT)
  • Foot-printing
  • Fingerprinting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the difference between foot-printing and fingerprinting?

A
  • Foot-printing: Maps out network layout focusing on TCP/IP stack info, routing topology, DNS, domains, hostnames.
  • Fingerprinting: Detects host systems focusing on open ports, OS types, versions, services.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an example of internal scanning?

A

Scanning from subnet #1 in vCluster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an example of external scanning?

A

Scanning from subnet #3 in vCluster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
  • systeminfo/hostnamectl
  • nmap
  • zenmap (GUI nmap)
  • unicornscan

What are these examples of?

A

Enumeration tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
  • traceroute
  • ifconfig/ipconfig
  • dig/nslookup
  • ping

What are these examples of?

A

Enumeration tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  • megaping
  • hping3
  • hostname
  • arp

What are these examples of?

A

Enumeration tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the goal of enumeration?

A

To scan/identify network ranges and hosts belonging to the target.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False: Passive enumeration requires an active connection to assets.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly