312-50 exam dumps

312-50 practice question 56 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 56

Single answer▪ Footprinting Countermeasures

A company discovers that external attackers are collecting detailed information about its internal naming conventions, employee contacts, and exposed services before attempting targeted attacks. During a review, the security team confirms that public DNS records expose unnecessary host details, several internet-facing systems respond with detailed service banners, and WHOIS entries reveal direct administrator contact information. The team wants to reduce its footprint without disrupting legitimate public-facing services such as email and the corporate website. Which action would provide the MOST effective immediate countermeasure against this kind of reconnaissance?

  1. A

    Implement split-horizon DNS, limit public DNS records to required entries only, suppress unnecessary service banners, and use role-based contact information in domain registration records

  2. B

    Disable DNS entirely for the organization, remove all MX records, and block HTTP/HTTPS traffic from the internet until a full security audit is completed

  3. C

    Increase password complexity requirements for all employees and enforce more frequent password rotation across internal systems

  4. D

    Deploy host-based antivirus on all public web and mail servers to prevent external users from gathering system information

  5. E

    Enable directory listing on public web servers so legitimate users can easily locate resources without querying DNS repeatedly

Show answer and explanation

Correct answer: A

Explanation

The best answer is the one that reduces externally visible information while maintaining required public services. In CEH context, footprinting countermeasures focus on minimizing information leakage from sources such as DNS, service banners, registrar records, websites, and public metadata. Common best practices include using split-horizon DNS or otherwise restricting zone data exposure, avoiding unnecessary public records, disabling or reducing service and application banners, sanitizing public-facing metadata, and using generic role accounts instead of personal contact information in domain registration where permitted by registrar and policy. Guidance from common operational security practices and vendor hardening documentation consistently recommends limiting information disclosure on internet-facing systems. The other options either fail to address reconnaissance directly or would unnecessarily disrupt business operations.

  • A. Correct.

    Correct. This option directly addresses multiple common footprinting vectors while preserving business operations. Split-horizon DNS helps ensure external users see only the limited DNS data necessary for public services, while internal records remain private. Reducing public DNS records to only required entries limits exposure of hostnames and architecture details. Suppressing service banners reduces version and platform disclosure from internet-facing services. Replacing personal administrator details in WHOIS or registrar contacts with role-based addresses reduces social engineering exposure. These are practical and standard countermeasures against reconnaissance.

  • B. Incorrect.

    Incorrect. Disabling DNS and removing MX records would break essential public services such as email delivery and website name resolution. While reducing exposure is important, footprinting countermeasures should balance security with operational requirements. This option is overly disruptive and not a realistic defensive approach for a functioning enterprise.

  • C. Incorrect.

    Incorrect. Strong password policy is important for authentication security, but it does not directly reduce publicly available footprinting data such as DNS records, service banners, or WHOIS contact details. A candidate might choose this because password hardening is a common security control, but it addresses a different phase of attack defense.

  • D. Incorrect.

    Incorrect. Antivirus can help detect or prevent malware on servers, but it does not meaningfully prevent passive or active footprinting techniques such as banner grabbing, DNS enumeration, or WHOIS lookups. This reflects a common misconception that endpoint protection mitigates all forms of external reconnaissance.

  • E. Incorrect.

    Incorrect. Enabling directory listing would increase information disclosure by exposing file and folder structures on public web servers. This would make footprinting easier, not harder. An attacker could use such listings to infer application structure, backup files, or sensitive content.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam