312-50 exam dumps

312-50 practice question 107 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 107

Single answerenumeration)

During an authorized internal assessment, you identify a Windows server exposing TCP 135, 139, and 445. The client wants to know whether domain user and group information can be gathered without valid credentials as part of the enumeration phase. Which action would be the MOST appropriate next step to verify whether null session enumeration is possible?

  1. A

    Attempt an anonymous SMB/RPC connection such as net use \\target\IPC$ "" /u:"" and then query available information with tools that use SAMR/LSA over RPC

  2. B

    Run a SYN flood against port 445 to determine whether the server falls back to guest access when overloaded

  3. C

    Use SQL authentication brute force against the host because user enumeration on Windows is primarily performed through MSSQL

  4. D

    Capture Kerberos AS-REQ traffic from the domain controller because null session enumeration requires Kerberos preauthentication to be disabled

Show answer and explanation

Correct answer: A

Explanation

This question focuses on practical Windows enumeration. When TCP 139 and 445 are exposed, a tester should consider SMB-based enumeration, including whether anonymous access is allowed. Historically, Windows null sessions allowed unauthenticated connections to IPC$ and, in some cases, RPC interfaces that could disclose usernames, groups, shares, or password policy information. The safest and most relevant next step is to test anonymous access directly rather than pivoting to unrelated attacks. In modern environments, such access is often restricted by default, but verification is still a valid part of enumeration during an authorized assessment. This aligns with common Windows security guidance around restricting anonymous SID/Name translation, SAM enumeration, and null session access over SMB/RPC as documented in Microsoft security best practices.

  • A. Correct.

    Correct. On Windows systems, null session enumeration historically involves attempting an anonymous connection to the IPC$ share and then using SMB/RPC-based interfaces such as SAMR or LSA to enumerate users, groups, shares, or policy information if the host is misconfigured to allow anonymous access. This is the most direct and appropriate verification step in an enumeration scenario involving ports 139/445.

  • B. Incorrect.

    Incorrect. A SYN flood is a denial-of-service technique, not an enumeration method, and it would be outside the scope of normal, minimally invasive verification during an authorized assessment unless explicitly approved. It also has no legitimate relationship to testing whether null sessions are permitted.

  • C. Incorrect.

    Incorrect. MSSQL may support account-related enumeration in some environments, but the presence of ports 135/139/445 specifically points to SMB/RPC-based Windows enumeration. User enumeration on Windows is not primarily performed through MSSQL, and this option ignores the most relevant exposed services.

  • D. Incorrect.

    Incorrect. Kerberos AS-REQ behavior is related to Kerberos authentication issues such as AS-REP roasting, not SMB null sessions. Null session enumeration does not depend on Kerberos preauthentication being disabled; it depends on anonymous access controls over SMB/RPC interfaces.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam