4_1_1 Section 4 – Operations and Incident Response - 4.1 – Security Tools - Reconnaissance Tools – Part 1

4_1_1 Section 4 – Operations and Incident Response - 4.1 – Security Tools - Reconnaissance Tools – Part 1

Created by
@UnmatchedMandolin

Questions and Answers

What is the main purpose of the traceroute command?

To map the entire path between two devices

Which command is used in Windows to achieve the same functionality as the traceroute command?

tracert

What type of error messages are used by the traceroute command to build the route?

ICMP Time to Live Exceeded

What is the purpose of the TTL parameter in IP packets?

<p>To prevent loops on the network</p> Signup and view all the answers

Why may there be gaps in the output of the traceroute command?

<p>Due to firewalls or routers filtering out ICMP messages</p> Signup and view all the answers

What is the mechanism by which packets are sent out to the network using the traceroute command?

<p>IP packets with incremental TTL</p> Signup and view all the answers

What protocol does Windows use for the traceroute command?

<p>ICMP</p> Signup and view all the answers

What type of messages are sent back to the original station when the Time To Live is exceeded?

<p>ICMP Time Exceeded</p> Signup and view all the answers

What is the main reason why the traceroute command may not work as well in Windows as in Linux or Mac OS?

<p>ICMP is blocked by firewalls</p> Signup and view all the answers

What is the purpose of the Time To Live (TTL) in a traceroute command?

<p>To prevent packets from circulating indefinitely</p> Signup and view all the answers

What is the default protocol used for the traceroute command in iOS?

<p>UDP</p> Signup and view all the answers

What happens when a packet's TTL reaches 0?

<p>It is dropped by the router</p> Signup and view all the answers

What is the purpose of the traceroute command?

<p>To determine the route to the destination</p> Signup and view all the answers

What is the difference between the ICMP Echo Request and ICMP Echo Reply?

<p>ICMP Echo Request is sent to the destination, while ICMP Echo Reply is sent back</p> Signup and view all the answers

What is the advantage of using different protocols for the traceroute command?

<p>It allows for more flexibility in network diagnostics</p> Signup and view all the answers

What is the outcome when the TTL is finally exceeded at the destination IP address?

<p>An ICMP Echo Reply is sent back</p> Signup and view all the answers

What is the purpose of running a traceroute?

<p>To identify the hop where a network problem is occurring</p> Signup and view all the answers

What does an exclamation mark 'Z' indicate in a traceroute result?

<p>Connection to the IP address is administratively prohibited</p> Signup and view all the answers

What is the purpose of the nslookup command?

<p>To query a DNS server for information about a domain</p> Signup and view all the answers

What is the dig command used for?

<p>To query a DNS server for information about a domain</p> Signup and view all the answers

What is the difference between the nslookup and dig commands?

<p>Nslookup provides less information than dig</p> Signup and view all the answers

What is the purpose of the ipconfig command in Windows?

<p>To determine the IP address of a device</p> Signup and view all the answers

What is the equivalent command to ipconfig in Linux and Mac OS?

<p>ifconfig</p> Signup and view all the answers

Why would you run a traceroute with multiple hops?

<p>To identify the path data takes to reach a destination</p> Signup and view all the answers

What is the purpose of the -n option when using the netstat command?

<p>To display only IP addresses and not resolve names</p> Signup and view all the answers

What is the purpose of running a DNS query using nslookup or dig?

<p>To gather information about a domain</p> Signup and view all the answers

What is the purpose of the ping command?

<p>To check if a device is communicating on the network</p> Signup and view all the answers

Why would you use the /all option with the ipconfig command?

<p>To get more detailed information about the IP configuration</p> Signup and view all the answers

What is the name of the command that combines the functionality of ping and traceroute in Windows?

<p>Pathping</p> Signup and view all the answers

What is the command used to view the ARP cache in Windows?

<p>arp -a</p> Signup and view all the answers

What is the purpose of the netstat command?

<p>To show network statistics and active connections</p> Signup and view all the answers

What is the purpose of the netstat command with the -a option?

<p>To display all active connections and the programs they are associated with</p> Signup and view all the answers

What is the purpose of the route command in Windows?

<p>To view the routing table</p> Signup and view all the answers

What is the IP address of the Google DNS server mentioned in the text?

<p>8.8.8.8</p> Signup and view all the answers

What is the default route designated by?

<p>0.0.0.0 with a netmask of 0.0.0.0</p> Signup and view all the answers

What is the name of the creator of the ping command?

<p>Mike Muuss</p> Signup and view all the answers

What does the ping command do when you run it?

<p>Checks if a device is communicating on the network</p> Signup and view all the answers

What is the command used to view the routing table in Linux and Mac OS?

<p>netstat -r</p> Signup and view all the answers

What does the pathping command do?

<p>Runs a traceroute to a destination IP address and measures the round-trip time</p> Signup and view all the answers

What is the purpose of using the netstat command with the -b option?

<p>To associate the Windows binary with the IP address conversation</p> Signup and view all the answers

What is the purpose of the netstat-b command in Windows?

<p>To show all active connections on the device</p> Signup and view all the answers

What is displayed when using the netstat command with the -a and -b options?

<p>All active connections and the programs they are associated with</p> Signup and view all the answers

What is the purpose of using the ARP command with the -a option?

<p>To view the ARP cache</p> Signup and view all the answers

What is the result of the pathping command to the IP address 8.8.8.8?

<p>100% packet loss on a particular hop</p> Signup and view all the answers

What is the purpose of the IPv6 address?

<p>To provide a unique identifier for a device on the network</p> Signup and view all the answers

What is the metric value of the default route in the given example?

<p>25</p> Signup and view all the answers

More Quizzes Like This

Network Administration Basics
8 questions
Network Administration Tasks Quiz
10 questions
Network Administration
10 questions

Network Administration

VibrantSalamander avatar
VibrantSalamander
Use Quizgecko on...
Browser
Browser