312-50 exam dumps

312-50 practice question 321 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 321

Single answer▪ Attack Access Controls

During an authorized internal security assessment, you obtain a low-privileged domain user account and discover that a legacy Windows file server still accepts NTLM authentication. The client asks you to demonstrate a realistic way an attacker could bypass access controls to reach restricted file shares without exploiting a software vulnerability on the server itself. Which action would MOST directly achieve that objective?

  1. A

    Perform an NTLM relay attack against the file server by capturing an authentication attempt from a privileged user and relaying it to the target service that does not require SMB signing

  2. B

    Run a TCP SYN flood against the file server so that it fails open and grants anonymous access to the restricted shares

  3. C

    Exploit SQL injection against the domain controller to modify the ACLs on the target file share

  4. D

    Use steganography to hide a malicious file in a shared folder and wait for the server to automatically elevate your access

Show answer and explanation

Correct answer: A

Explanation

The best answer is the NTLM relay attack because it is a well-known and realistic method of attacking access controls in Windows environments where NTLM is still enabled and relay protections are not enforced. In practice, attackers use tools such as Responder and ntlmrelayx during authorized assessments to capture or coerce authentication and relay it to services like SMB, LDAP, or HTTP when defenses are weak. This can result in unauthorized access to restricted resources under the security context of the relayed user. Microsoft guidance has long recommended mitigating relay attacks by enabling SMB signing where appropriate, reducing NTLM usage, enforcing LDAP signing/channel binding where applicable, and adopting stronger authentication controls. The other options are incorrect because they either describe availability attacks, unrelated attack classes, or techniques that do not actually alter or bypass authorization decisions.

  • A. Correct.

    Correct. NTLM relay is a practical access-control attack when a target service accepts NTLM authentication and lacks protections such as SMB signing or EPA/channel binding in applicable protocols. By relaying a captured authentication attempt from a more privileged user to the file server, an attacker may authenticate as that user and access restricted resources without needing to crack the password or exploit a software flaw on the server. This directly targets trust in the authentication workflow, which is an access-control weakness rather than a memory-corruption or code-execution issue.

  • B. Incorrect.

    Incorrect. A SYN flood is a denial-of-service attack that attempts to exhaust connection resources. It does not cause a Windows file server to "fail open" and grant access to restricted SMB shares. This option reflects a common misconception that availability attacks can be used to bypass authentication or authorization controls directly.

  • C. Incorrect.

    Incorrect. SQL injection is a real technique for attacking poorly secured web applications and databases, but it is unrelated to the scenario presented unless a vulnerable SQL-backed application is actually involved. The question specifically asks for a method that bypasses access controls on the file server without exploiting a software vulnerability on that server. Introducing SQL injection against a domain controller is also not a realistic or appropriate description of how domain controllers are typically attacked.

  • D. Incorrect.

    Incorrect. Steganography is used to conceal data within other files, often for evasion or covert transfer. It does not grant elevated privileges or cause a file server to increase a user's access rights. This distractor targets confusion between payload concealment and privilege or authorization bypass.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam