312-50 exam dumps

312-50 practice question 104 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 104

Single answerUnix/Linux, Telnet, FTP, TFTP, SMB, IPv6, and BGP

During an authorized internal assessment of a Linux-based branch office, you discover that the edge router advertises an IPv6 prefix to the LAN while also establishing eBGP sessions with an upstream provider. A dual-stack Linux server in the branch is running legacy services for operations staff, including Telnet, FTP, TFTP, and SMB. The client wants you to identify the most serious issue that could allow an attacker on the local IPv6 segment to gain administrative control of network infrastructure with the least effort. Which finding is the BEST answer?

  1. A

    The Linux server allows anonymous FTP login, which could let an attacker upload a file and directly modify the router's BGP table

  2. B

    The router accepts unauthenticated TFTP transfers for configuration backup and restore over the local IPv6 segment, exposing the risk of config theft or malicious replacement

  3. C

    The SMB service on the Linux server supports file sharing, which means an attacker can inherently hijack the eBGP session by relaying SMB authentication

  4. D

    The Telnet service on the Linux server uses cleartext authentication, which is risky, but it does not by itself provide the most direct path to taking control of the router

Show answer and explanation

Correct answer: B

Explanation

The key is to prioritize the finding that most directly enables compromise of network infrastructure. TFTP is a UDP-based file transfer protocol designed to be simple; it lacks authentication and encryption. In real environments, routers and switches often use TFTP for image transfer or configuration backup/restore. If such services are exposed on the local IPv6 segment, an attacker may be able to obtain sensitive configuration data or push malicious changes, which can affect interfaces, ACLs, credentials, and BGP policy. That makes it a more direct route to administrative control than insecure services hosted only on the Linux server.

By comparison, Telnet and FTP are also insecure because they transmit credentials in cleartext unless otherwise encapsulated, but they do not automatically grant control of the router. SMB exposure may create lateral movement risk, but it does not inherently affect BGP. From a CEH perspective, the best answer is the one that ties protocol weakness to realistic exploitation impact on the actual target asset.

Relevant best-practice references include IETF RFC 1350 for TFTP behavior and standard vendor hardening guidance from Cisco, Juniper, and other network vendors recommending restriction or replacement of TFTP and Telnet for device management. For secure administration, SSH and authenticated file transfer mechanisms such as SCP/SFTP are preferred, and infrastructure management access should be tightly filtered for both IPv4 and IPv6.

  • A. Incorrect.

    Anonymous FTP is a legitimate security concern because it can expose or permit transfer of files depending on server configuration. However, FTP access to a Linux server does not directly imply the ability to alter a router's BGP table. That would require access to the router itself or to a management workflow that imports files from that FTP server. The option overstates FTP's impact and incorrectly assumes direct BGP manipulation.

  • B. Correct.

    This is the best answer. TFTP provides no authentication and no encryption, and many network devices historically use it for configuration backup and restore. If a router is reachable over the local IPv6 segment and accepts TFTP-based config operations, an attacker may be able to retrieve the current configuration, learn credentials or routing policy details, or replace the startup/running configuration depending on device settings and ACLs. Because the router is the infrastructure device maintaining the BGP session, compromise of its configuration is a direct path to administrative control and routing manipulation.

  • C. Incorrect.

    SMB can be abused in various attack paths, especially where weak authentication, legacy dialects, or relay conditions exist. However, SMB file sharing on a Linux host does not inherently allow BGP session hijacking. BGP session compromise depends on access to the routing device, BGP credentials if used, TCP session manipulation, or control-plane weaknesses. This option conflates unrelated protocols and overgeneralizes the effect of SMB exposure.

  • D. Incorrect.

    Telnet is insecure because credentials and session data are sent in cleartext, making sniffing and credential theft feasible on a local segment. That is a serious issue, especially on IPv6 LANs where assessors may overlook local exposure. However, in this scenario, Telnet is on the Linux server, not necessarily on the router. Even if compromised, it is not as direct or as impactful as unauthenticated TFTP access to the router's configuration itself. Therefore this is true but not the best answer.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam