312-50 exam dumps

312-50 practice question 110 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 110

Single answer▪ Enumeration Countermeasures

A company completed an internal security assessment and discovered that unauthenticated users on the corporate network can enumerate Active Directory usernames through SMB and RPC-based queries against a legacy Windows file server. The server must remain online for business operations, but the security team wants to reduce the risk of account harvesting without breaking legitimate domain functionality. Which action is the MOST effective enumeration countermeasure in this scenario?

  1. A

    Disable anonymous SID/Name translation and restrict anonymous access such as null sessions on the legacy server

  2. B

    Enable NetBIOS over TCP/IP on all hosts so name resolution is handled consistently across the network

  3. C

    Increase the domain account lockout threshold to reduce help desk tickets from failed logons

  4. D

    Allow inbound SMB only from domain-joined clients while blocking all RPC traffic from internal subnets

  5. E

    Turn off Windows event logging for failed logon attempts to prevent attackers from learning which usernames are valid

Show answer and explanation

Correct answer: A

Explanation

The best answer is to disable anonymous SID/Name translation and restrict null sessions or other anonymous access paths on the legacy Windows server. In Windows environments, enumeration often occurs through SMB/RPC mechanisms when anonymous or overly permissive access is allowed. The goal of an enumeration countermeasure is to minimize information disclosure to unauthenticated users while preserving required authenticated services. Microsoft security baselines and policy guidance have long recommended restricting anonymous enumeration of SAM accounts and shares, limiting null session exposure, and reducing reliance on legacy services. Additional supporting controls can include host-based firewall rules, SMB signing where appropriate, network segmentation, and disabling unnecessary legacy protocols such as NetBIOS where feasible. However, among the listed options, directly hardening anonymous access is the most accurate and least disruptive mitigation for the scenario described.

  • A. Correct.

    Correct. A common Windows enumeration path is anonymous access through null sessions and related RPC/SMB mechanisms that can expose user, group, and SID information. Restricting anonymous access and disabling anonymous SID/Name translation directly addresses the account-enumeration weakness while preserving normal authenticated domain operations. This aligns with long-standing Microsoft hardening guidance around policies such as 'Network access: Do not allow anonymous enumeration of SAM accounts' and related anonymous access restrictions.

  • B. Incorrect.

    Incorrect. Enabling NetBIOS over TCP/IP generally increases exposure to legacy name service and enumeration techniques rather than reducing them. NetBIOS and related services have historically been abused for host and user enumeration. A candidate might choose this option thinking consistency improves security, but consistency of an insecure service does not mitigate enumeration risk.

  • C. Incorrect.

    Incorrect. Account lockout threshold settings affect brute-force resistance and operational usability, not the root cause of anonymous username enumeration. Raising the threshold could actually make password-guessing attacks easier by permitting more failed attempts. This option reflects a common confusion between authentication attack mitigation and enumeration countermeasures.

  • D. Incorrect.

    Incorrect. Restricting SMB access to authorized clients can be helpful as part of network segmentation, but blocking all RPC traffic from internal subnets is overly broad and likely to disrupt legitimate Windows administration, domain communication, or application dependencies. The question asks for the most effective countermeasure that reduces enumeration without breaking business functionality; targeted anonymous-access hardening is more precise and realistic.

  • E. Incorrect.

    Incorrect. Disabling event logging reduces defensive visibility and incident response capability. It does nothing to stop enumeration and would violate security monitoring best practices. Attackers do not rely on the victim's event logs to validate usernames; defenders rely on those logs to detect suspicious activity.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam