312-50 exam dumps

312-50 practice question 138 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 138

Single answer▪ Vulnerability Exploitation

During an authorized internal penetration test, you identify a Linux web server running a vulnerable version of Samba that appears susceptible to the username map script command execution flaw (CVE-2007-2447). The client has approved controlled exploitation only if it minimizes service disruption and provides strong proof of impact. Which action is the MOST appropriate next step for the ethical hacker?

  1. A

    Use a targeted Samba exploit to execute a benign command such as 'id' and capture the output as proof of remote code execution

  2. B

    Launch a denial-of-service test against the SMB service to prove the server is vulnerable

  3. C

    Run a password-spraying attack against SMB accounts to gain access without exploiting the vulnerability

  4. D

    Immediately upload a persistent reverse shell to the server to maintain long-term access for further testing

Show answer and explanation

Correct answer: A

Explanation

The key principle in vulnerability exploitation during an authorized assessment is to use the least intrusive technique that reliably proves impact. In this scenario, CVE-2007-2447 is a well-known Samba command execution vulnerability affecting certain Samba 3.x configurations through the username map script feature. A focused exploit that runs a harmless command such as 'id', 'uname -a', or 'whoami' is the best next step because it confirms remote code execution without unnecessarily altering the system or degrading service. By contrast, denial-of-service testing proves availability impact rather than code execution, password spraying tests authentication weaknesses instead of the discovered vulnerability, and installing persistence exceeds what is needed for initial proof. This approach is consistent with professional penetration testing standards emphasizing safety, scope control, evidence collection, and minimal impact. References include the Samba security advisory for CVE-2007-2447 and common industry guidance such as NIST SP 800-115, which recommends controlled validation of vulnerabilities with careful attention to operational risk.

  • A. Correct.

    Correct. In a controlled engagement, the most appropriate exploitation step is to validate the vulnerability with the least invasive method that still demonstrates impact. Executing a harmless command such as 'id' provides clear evidence of remote code execution while minimizing operational risk. This aligns with common penetration testing best practices: prove exploitability, avoid unnecessary persistence, and limit actions to what is explicitly authorized.

  • B. Incorrect.

    Incorrect. A denial-of-service test does not validate remote code execution and introduces unnecessary risk to service availability. Even if disruption testing is in scope, it would not be the preferred next step when the objective is to safely confirm exploitability with minimal impact.

  • C. Incorrect.

    Incorrect. Password spraying is a different attack path and does not confirm exploitation of the identified Samba vulnerability. It also increases the risk of account lockouts and may violate engagement constraints if credential attacks were not specifically approved.

  • D. Incorrect.

    Incorrect. Uploading a persistent reverse shell is excessive for initial validation and creates avoidable risk. Persistence mechanisms should not be deployed unless explicitly authorized and operationally necessary. For CEH-style methodology, the ethical hacker should first demonstrate code execution with a benign, reversible action.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam