312-50 exam dumps

312-50 practice question 323 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 323

Single answer▪ Attack Access Controls

During an authorized internal assessment, a CEH tester gains a low-privileged domain user account through phishing. The client wants to know whether weak access control configuration could allow movement into sensitive file shares without exploiting software vulnerabilities. The tester discovers several SMB shares and wants to identify which access control weakness would most directly allow unauthorized access to confidential files by an authenticated but low-privileged user. Which finding BEST demonstrates a successful attack against access controls?

  1. A

    A file server allows the Domain Users group read access to a share containing HR salary spreadsheets that should be restricted to HR staff only.

  2. B

    The SMB service on the file server only supports SMB signing but not SMB encryption.

  3. C

    The file server uses NTFS permissions instead of only share permissions.

  4. D

    A domain controller responds to ICMP echo requests from internal hosts.

Show answer and explanation

Correct answer: A

Explanation

The best answer is the overly permissive file share granted to Domain Users. In access control attacks, the goal is often to abuse weak authorization rather than exploit a software flaw. A low-privileged authenticated account should not be able to access data outside its assigned role. When confidential HR files are readable by a broad group such as Domain Users, the tester has demonstrated a practical and serious authorization weakness.

This aligns with common security best practices such as least privilege and need-to-know access. Microsoft guidance on securing Windows file shares and NTFS permissions emphasizes carefully assigning permissions to only the required users and groups, and regularly reviewing effective access. From a CEH perspective, this is a realistic example of attacking access controls through misconfiguration rather than malware or kernel exploitation.

The other options are plausible distractors because they are security-relevant findings, but they do not directly prove unauthorized resource access by the low-privileged user. The key distinction is whether the finding shows a failure in authorization enforcement.

  • A. Correct.

    Correct. This is a classic access control failure: permissions are overly broad, granting an authenticated low-privileged group access to sensitive data outside its business need. In a real engagement, demonstrating that Domain Users can read HR-only files shows a breakdown of least privilege and authorization controls, which is directly relevant to attacking access controls.

  • B. Incorrect.

    Incorrect. Lack of SMB encryption may expose data in transit under some conditions, but it does not by itself grant a low-privileged user unauthorized access to files. SMB signing is primarily intended to help protect against tampering and relay-related issues, while encryption protects confidentiality of SMB traffic. This is a transport security concern, not an authorization failure.

  • C. Incorrect.

    Incorrect. Using NTFS permissions is normal and often necessary for granular access control on Windows file servers. In practice, effective access is typically determined by the combination of share permissions and NTFS ACLs, with NTFS permissions providing finer control. The mere presence of NTFS permissions does not indicate weak access control.

  • D. Incorrect.

    Incorrect. ICMP echo responses may assist host discovery during reconnaissance, but they do not represent unauthorized access to protected resources. This finding is related to network exposure or information gathering, not a successful attack against authorization or access control mechanisms.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam