exam questions

Exam N10-007 All Questions

View all questions & answers for the N10-007 exam

Exam N10-007 topic 1 question 22 discussion

Actual exam question from CompTIA's N10-007
Question #: 22
Topic #: 1
[All N10-007 Questions]

A penetration tester has been tasked with reconnaissance to determine which ports are open on the network. Which of the following tasks should be done FIRST?
(Choose two.)

  • A. Network scan
  • B. Banner grab
  • C. Tracert
  • D. DHCP server check
  • E. Brute-force attack
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
waveyzalgos
Highly Voted 5 years, 1 month ago
The answer is A and C because the question is asking what they should do FIRST. Banner Grab is done AFTER you determine what systems have open ports.
upvoted 17 times
betty_boop
4 years, 8 months ago
yes! thank you for this answer. Just read this from Mike's book: Having found an open port, another way for a malicious user to gain information and additional access is to probe a host’s open ports to learn details about running services. This is known as banner grabbing.
upvoted 5 times
...
...
Erodriguez812
Highly Voted 5 years, 2 months ago
No its AC study you should study the exam objectives alittle more
upvoted 11 times
...
Granddude
Most Recent 3 years, 3 months ago
Selected Answer: AB
Traceroute is only going to show you the route
upvoted 1 times
...
DarryJan
4 years, 1 month ago
First start with; A penetration test is an active test that attempts to exploit discovered vulnerabilities. It starts with a vulnerability scan and then bypasses or actively tests security controls to exploit vulnerabilities. A Network/port scanner scans systems for open ports and attempts to discover what services and protocols are running. Banner grabbing queries remote systems to detect their operating system, along with services, protocols, and applications running on the remote system. Pick your answer this. Tracert—A command-line tool used to trace the route between two systems.
upvoted 2 times
...
mfombi
4 years, 5 months ago
Once you agree that A is part of the answer then B becomes pointless really because Network Scanning does what B does plus more. Purpose of network scanning: a)To discover live hosts/computer, IP address, and open ports of the victim. b)To discover services that are running on a host computer. c)To discover the Operating System and system architecture of the target. d)To discover and deal with vulnerabilities in Live hosts. https://www.w3schools.in/ethical-hacking/scanning-techniques/
upvoted 1 times
...
CrazyFat
4 years, 6 months ago
Port Scan & Banner Grab. It's not a tracert because traceroute works at the network layer (OSI layer 3) and TCP or UDP ports are defined in either layer 4 of the OSI model.
upvoted 3 times
...
KLT316
4 years, 7 months ago
How does tracert help determine PORTS that are open?!
upvoted 3 times
b0ugi3
4 years ago
Only thing that comes to mind is watching which ports the packets are using, but my initial answers were network scan+banner grab
upvoted 1 times
...
...
[Removed]
4 years, 9 months ago
Correct answers are : A. Network scan B. Banner grab More information : https://www.giac.org/paper/gsec/2473/network-reconnaissance-detection-prevention/104296 Banner grabbing is a technique used to gain information about a computer system on a network and the services running on its open ports. More information : https://en.wikipedia.org/wiki/Banner_grabbing
upvoted 2 times
Huh
4 years, 8 months ago
"First" is the most important part of this question, as some people already pointed out, you need to know where things are 1st before you decide to find more information about those systems.
upvoted 3 times
...
...
Charcoal2899
5 years ago
The answer must be A and C. It's definitely not D or E, leaving us with A, B and C. Since we are asked what to do first it would make sense to check the system is online, understand what hops are required to reach X destination and also to perform a network scan to determine what ports are open. I believe a banner grab would only be performed after these steps were completed! Not to mention that banner grabs are not covered within the exam objectives so that alone should help us narrow things down a little.
upvoted 5 times
...
Poppins
5 years, 1 month ago
The answer definitely includes B. I mean that's EXACTLY what be does. It literally tells you everything running on every open port.
upvoted 3 times
...
Realityishere1995
5 years, 1 month ago
The answer should be A and B. Network Scan: Network scanning refers to the use of a computer network to gather information regarding computing systems | Banner grab: Banner grabbing is a technique used to gain information about a computer system on a network and the services running on its open ports
upvoted 3 times
...
BOT007
5 years, 5 months ago
The answer should be Port Scan & Banner Grab(so A and B)
upvoted 7 times
Lynot123
4 years, 5 months ago
why not AC?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...