312-50 exam dumps

312-50 practice question 109 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 109

Single answer▪ Enumeration Countermeasures

During an internal security assessment, a tester is able to use null SMB sessions and unauthenticated RPC queries against several legacy Windows file servers to enumerate local users, group memberships, and shared resources. The systems must continue to provide SMB-based file sharing to authenticated employees, and the operations team wants the most effective countermeasure that reduces enumeration without breaking normal access. Which action is the BEST recommendation?

  1. A

    Disable anonymous SID/Name translation and restrict anonymous access so unauthenticated users cannot enumerate SAM accounts and shares

  2. B

    Block TCP 445 for all hosts on the internal network while keeping SMB available for authenticated users

  3. C

    Disable NetBIOS over TCP/IP on all servers to eliminate SMB enumeration while preserving all current SMB functionality

  4. D

    Rename the built-in Administrator account to prevent null session enumeration of users and shares

Show answer and explanation

Correct answer: A

Explanation

The key issue is unauthenticated enumeration over SMB/RPC, not authenticated file-sharing itself. The best countermeasure is to harden Windows anonymous access settings so that null sessions cannot enumerate SAM accounts, groups, SIDs, and shares. In practice, this aligns with Microsoft security guidance around restricting anonymous access and auditing legacy compatibility settings that permit anonymous enumeration. Additional defense-in-depth measures can include reducing exposure of SMB through segmentation, disabling unnecessary legacy protocols, and enforcing least privilege, but those do not address the root cause as directly as restricting anonymous enumeration. CEH candidates should recognize that effective enumeration countermeasures focus on limiting information disclosure while preserving required services for authenticated users.

  • A. Correct.

    Correct. In Windows environments, enumeration via null sessions and unauthenticated RPC/SMB queries is mitigated by restricting anonymous access and disabling anonymous enumeration capabilities such as SAM account and share enumeration where supported by policy. Practical countermeasures include hardening security options and local/domain policies related to anonymous access, such as preventing anonymous enumeration of SAM accounts and shares and limiting anonymous SID/Name translation. This directly addresses the attack path while preserving authenticated SMB access for legitimate users.

  • B. Incorrect.

    Incorrect. Blocking TCP 445 internally would disrupt normal SMB file sharing, which directly conflicts with the business requirement to keep SMB available for authenticated employees. Although segmentation and firewalling can reduce exposure between network zones, blocking 445 for all internal hosts is not a realistic countermeasure in this scenario.

  • C. Incorrect.

    Incorrect. Disabling NetBIOS over TCP/IP may reduce some legacy NetBIOS-based enumeration, but modern SMB commonly operates directly over TCP 445 and can still be enumerated if anonymous access is allowed. This option may help in some environments, but it does not specifically stop null-session or unauthenticated RPC enumeration and is therefore not the best answer.

  • D. Incorrect.

    Incorrect. Renaming the built-in Administrator account is a hardening step that can reduce trivial guessing and some targeted attacks, but it does not prevent anonymous enumeration of users, groups, or shares through SMB/RPC. This is a common misconception: obscuring one account name does not solve the underlying anonymous access issue.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam