Week 05 - Network Analysis Tools 1 (L11-L13) Flashcards

1
Q

What is the host file?

A

Local file that maps IP address to host names

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is ping?

A

Windows command to check if host is alive. Sends ICMP packets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What can be identified with port scanning?

A

Open ports of a system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the arp command?

A

Shows local ARP table. MAC address to IP address. Two modes: static & dynamic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Name ports for: http, smtp, telnet, dns, ftp, DHCP, ssh, imap, pop

A

80 (http), 25 (smtp), 21 (ftp), 53 (dns), 21 (ftp), 63 (dhcp), 22 (ssh), 143 (imap), 110 (pop)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are IPID?

A

IP Identification Number. Attacker might see how many packets are already sent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are well known ports?

A

Reserved system ports defined by IANA. The first 1024 ports are reserved

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is tracert?

A

Tracert shows route of an IP packet to his destination (hop by hop)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is ipconfig?

A

Windows command to configure NIC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is nslookup?

A

sends request to DNS to resolve either IP or domain name

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is TTL? Why is it required?

A

Time To Live: Time a network packets will be send around in a network before it gets dropped.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is TCPview and Superscan?

A

Port scanning tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is netstat?

A

Netstat shows all network connections which are currently open.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Explain Stealth Scan and TCP Connect San?

A

Stealth Scan: sends SYN packet, host will respond with SYN-ACK. Full connection never established

TCP Connect Scan: This scan creates a connection. ACK will be send. Only works on open ports.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is NMAP?

A

Very powerful network scanner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly