SY0-701 exam dumps

SY0-701 practice question 288 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 288

Single answerEnumeration

A security analyst is reviewing the results of an internal assessment on a Windows-based network. The tester was able to connect to several hosts over SMB and, without exploiting a vulnerability, gather lists of shared folders, local users, and group membership information from systems that should expose minimal information. The analyst wants to reduce this type of information disclosure while preserving normal file-sharing operations for authorized users. Which action would BEST address the issue?

  1. A

    Disable anonymous/null session access and restrict SMB share and object enumeration to authenticated, authorized users

  2. B

    Block all outbound HTTPS traffic from the affected servers

  3. C

    Install a host-based intrusion prevention system to automatically quarantine enumerating clients

  4. D

    Enable full-disk encryption on the affected systems

Show answer and explanation

Correct answer: A

Explanation

This question focuses on enumeration, which is the process of extracting useful details from systems and services after discovering them. In real environments, SMB, NetBIOS, LDAP, SNMP, DNS, and similar services are common enumeration targets. The scenario describes an assessor collecting lists of shares, users, and group memberships without exploitation, which points to excessive information exposure through access control weaknesses rather than malware or a software flaw. The best mitigation is to reduce anonymous and unnecessary authenticated visibility by disabling null sessions/anonymous enumeration where supported, enforcing least privilege on shares and objects, and hardening SMB-related settings. This aligns with general Microsoft security baselines and least-privilege best practices: expose only the information and resources necessary for authorized operations. Other controls such as HIPS and disk encryption may be valuable in a defense-in-depth strategy, but they do not directly remediate enumeration exposure over SMB.

  • A. Correct.

    Correct. Enumeration often involves gathering information such as users, groups, shares, and services using legitimate protocols and misconfigurations rather than exploiting code execution flaws. In Windows environments, excessive SMB/NetBIOS exposure and permissive anonymous access can allow null-session-style enumeration or overly broad authenticated enumeration. Disabling anonymous access where possible, tightening share permissions, and limiting enumeration to authorized users directly addresses the root cause while preserving business-required file sharing.

  • B. Incorrect.

    Incorrect. Blocking outbound HTTPS does not address SMB-based enumeration occurring inside the network. This option may sound reasonable if someone is thinking about command-and-control or data exfiltration, but the scenario is about information disclosure through network service enumeration, not web traffic.

  • C. Incorrect.

    Incorrect. A host-based intrusion prevention system may detect or rate-limit some suspicious behavior, but it does not directly fix the misconfiguration that permits unnecessary enumeration. Enumeration can occur through normal administrative protocols and may not be inherently malicious, so relying on automated quarantine could also disrupt legitimate administration.

  • D. Incorrect.

    Incorrect. Full-disk encryption protects data at rest if a device is lost or stolen, but it does not prevent a remote user from querying exposed network services on a running system. This is a common misconception: encryption at rest does not mitigate online service enumeration.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam