Skip to content
ScopefileGet the app

Module 4Domain 2 of 9Reconnaissance Techniques

Enumeration: which service gives away what

Enumeration is where recon gets specific: querying the services a scan found and pulling out names, shares, accounts and configuration. Module 4 is largely a matching exercise, pairing each service with the kind of detail it can expose and the countermeasure that closes it.

Exam
312-50
Domain
2 of 9
Domain weight
17%
This file
~6%
Targets
17

The last stop in recon

Enumeration closes the Reconnaissance Techniques domain, 17% of the exam (as of Oct 11, 2026) under EC-Council's blueprint v5.0, after scanning has established what is listening. It is louder than scanning, because now you are holding conversations with services rather than knocking on ports, so a target that logs anything records it.

The blueprint names the services to know: NetBIOS, SNMP, LDAP, NTP and NFS, SMTP and DNS, SMB and the rest, plus their countermeasures. The module rewards a clean lookup, each service against the information it gives up and the setting that stops it, so the service table below carries most of the weight.

Which service gives away what

Service, the detail it can expose, and the countermeasure.
ServiceWhat it can exposeCountermeasure
NetBIOSMachine names, shares and sessions on older Windows networksDisable where unused; block the ports at the perimeter
SMBShares and session detail, especially through anonymous accessRestrict anonymous access; segment and patch file sharing
SNMPDevice and system configuration if left on defaultsDrop default community strings; use authenticated SNMPv3
LDAPDirectory structure: users, groups and organizational layoutRequire authentication; limit anonymous bind and query scope
SMTPWhether an address is a valid recipient, through verify and expand responsesDisable those commands; do not confirm account existence
DNSInternal host inventory, if zone transfers are open to anyoneRestrict transfers to known secondaries; split internal and external zones
NTP and NFSHost lists, time sources and exported file systemsRestrict queries and exports to known hosts

Terms around the table

Anonymous access
A service answering without credentials. It yields the richest enumeration, and removing it is the first countermeasure for most services.
Null session
An unauthenticated connection to a Windows service that older configurations allowed, exposing shares and account detail.
Community string
The shared secret older SNMP versions use in place of real authentication. Leaving it at a default value is the classic SNMP exposure.

The countermeasures rhyme

Read down the countermeasure column and the same three moves repeat: remove anonymous access, require authentication, and segment the service away from anyone with no business reaching it. That pattern is worth more than memorizing each row, because a service you have not studied still yields to it.

For the tester, the defensive view is the useful one. If you know which setting closes a leak, you also know what its absence looks like in a result, which is the thing a scenario is usually describing.

Name the service, name the fix

Service-identification and short judgment items. Decide the service or the fix first, then read the note on each option.

Answered 0/17Hits 0

T-01

During an assessment, you successfully parse returned SNMP OIDs to reveal running processes and installed software. You notice a hidden HTTP daemon listening on an obscure high port. Which technique best enumerates its available directories?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe http-title script only fetches the page title, which identifies the site but does not list its directories.
  2. BThe snmpget utility retrieves SNMP OID values and cannot browse an HTTP server's directory structure.
  3. CCorrect: the http-enum NSE script checks a web server for common directories and applications, suited to mapping a newly found HTTP service.
  4. DThe smb-enum-shares script lists Windows file shares over SMB and does not apply to an HTTP daemon.
T-02

You must acquire a target domain user list. How does passive OSINT collection compare to performing an active anonymous LDAP bind using overly broad search filters?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABroad LDAP queries hit the domain controller directly and can be logged, while OSINT does not touch the target network at all.
  2. BAn LDAP bind is an active connection to the directory, not passive monitoring, and an anonymous bind yields no credentials.
  3. COSINT relies on public sources and never queries the domain controller; direct queries are what LDAP enumeration does.
  4. DCorrect: OSINT leaves no trace on the target but usually yields a partial user list, whereas a broad LDAP query is fuller but detectable.
T-03

Which of the following information is NOT typically gathered through SNMP enumeration?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASNMP exposes configuration details such as interfaces, routing tables and system descriptions, so it is commonly gathered.
  2. BSNMP MIBs describe hardware such as interfaces, storage and sometimes model information, which enumeration routinely collects.
  3. CInterface counters and traffic statistics are core SNMP data, so network statistics are typically gathered.
  4. DCorrect: SNMP does not provide a browsable view of a file system's contents; that comes from file-sharing protocols such as SMB or NFS.
T-04

During an engagement, you find an exposed IPC$ share with anonymous access on a network workstation. Why is it flawed to assume the domain controllers share this identical vulnerability?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: domain controllers usually receive hardened baselines and Group Policy restricting anonymous access, so a weak workstation setting cannot be assumed to apply.
  2. BNo exclusive MFA requirement exists for IPC$ on domain controllers; the share is authenticated with standard Windows mechanisms.
  3. CDomain controllers also host administrative shares, plus SYSVOL and NETLOGON, so this distinction is false.
  4. DDomain controllers rely heavily on SMB for Group Policy and logon scripts, so SMB is never disabled on them by default.
T-05

Which of the following is NOT a type of network enumeration?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASNMP enumeration queries network devices for configuration and system information, a standard enumeration technique.
  2. BCorrect: antivirus scanning examines files for malware on a host; it does not query network services for users, shares or configuration.
  3. CLDAP enumeration queries directory services for users, groups and organizational details, a standard enumeration technique.
  4. DNetBIOS enumeration retrieves names, shares and workgroup details from Windows hosts, a classic enumeration technique.
T-06

After enumerating a healthcare network, you discover multiple open services. Which specific enumeration finding should be prioritized as the most critical risk during the vulnerability reporting phase?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA host answering pings is low-impact reconnaissance, not the gravest finding in a regulated healthcare environment.
  2. BInternal routing chatter is a configuration note, far below exposure of regulated patient data.
  3. CCorrect: in healthcare, exposures that let unauthorized parties reach protected health information carry the heaviest compliance and business impact, so they lead the report.
  4. DA stale banner on a non-critical internal service is minor next to a regulated-data exposure.
T-07

During which phase does an attacker establish active network sessions to gather detailed information about services running on target machines?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: enumeration creates active connections to services such as SMB, SNMP or LDAP to extract users, shares and configuration details.
  2. BReconnaissance gathers information largely from public or passive sources before connecting to target services.
  3. CScanning identifies live hosts and open ports but does not usually establish sessions to pull detailed service data.
  4. DExploitation uses discovered weaknesses to gain access, and comes after the information-gathering phases.
T-08

A vulnerability report flags a production web server as critically vulnerable based solely on an exposed "Apache/2.4.49" HTTP header. Why should this specific finding be initially categorized as unverified?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AHTTP headers do not randomize version numbers; the string is whatever the server is configured to send, possibly edited or suppressed.
  2. BDefault Apache installations answer normal requests, so they are not immune to probing and this does not explain the uncertainty.
  3. CScanners mostly rely on banner and version checks rather than exploitation, which is exactly why banner-only findings need confirmation.
  4. DCorrect: a version banner can be altered, backported or unrelated to the vulnerable configuration, so it suggests risk without proving the flaw is exploitable.
T-09

You are investigating a network for potential security issues and discover that several devices use the SMB protocol for file sharing. Which of the following tools would you use to enumerate SMB information?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Enum4linux wraps Samba tools to pull users, groups, shares, password policy and OS details from SMB hosts.
  2. BSMBMapper is not a recognized enumeration tool; the similarly named SMBMap exists, but it is not the classic answer here.
  3. CSMBScan is not a standard, widely used SMB enumeration tool in common security toolkits.
  4. DNetShareEnum is a Windows API function that tools call to list shares, rather than a standalone enumeration tool itself.
T-10

While reviewing network traffic logs to identify internal naming conventions, you notice broadcast queries on UDP port 137. Which name resolution mechanism is generating these specific network artifacts?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ALLMNR uses multicast on UDP port 5355, not broadcasts on port 137, though it is often abused alongside NetBIOS name resolution.
  2. BDHCP assigns addresses using UDP ports 67 and 68 and does not resolve host names on port 137.
  3. CCorrect: NetBIOS Name Service uses UDP port 137, and its broadcast name queries reveal Windows host and domain naming conventions.
  4. DDNS normally uses unicast queries to port 53 on configured servers, not local broadcasts on port 137.
T-11

Which of the following Windows PowerShell cmdlets would display detailed information about users in a domain, including their login names, email addresses, and last logon times?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Get-ADUser from the ActiveDirectory module retrieves domain user objects, and with extra properties it shows email and last logon data.
  2. BGet-Process lists running processes on a computer and has nothing to do with domain user accounts.
  3. CGet-EventLog reads classic Windows event logs; logon events appear there, but it does not list user account attributes.
  4. DGet-Service lists Windows services and their status, not information about domain users.
T-12

Which of the following is a SNMP enumeration tool?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ALDAP enumeration tools query directory services over LDAP, not SNMP agents on network devices.
  2. BNbtstat displays NetBIOS name tables and sessions on Windows, which is NetBIOS enumeration rather than SNMP.
  3. CThe net view command lists shared resources and computers over NetBIOS/SMB, not SNMP data.
  4. DCorrect: SolarWinds network management tools query SNMP agents, and its toolset is commonly cited for SNMP enumeration of devices.
T-13

An attacker is using port 389 traffic to gain information about the structure of a network's directory services. What service is this attacker likely targeting?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASNMP uses UDP ports 161 and 162 for device management, not TCP 389.
  2. BSMTP uses port 25 (and 587 for submission) for mail transfer, not directory queries.
  3. CNetBIOS uses ports 137 through 139 for name, datagram and session services rather than 389.
  4. DCorrect: LDAP listens on port 389 (636 for LDAPS) and exposes directory structure such as users, groups and organizational units.
T-14

Which protocol is used to monitor and manage system performance by collecting and analyzing operational data such as CPU usage, memory usage, and network activity?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AHTTP transfers web content; it is not the standard protocol for collecting device performance counters.
  2. BCorrect: SNMP lets management stations poll devices for CPU, memory, interface and traffic statistics, which is also why exposed agents leak information.
  3. CSMTP moves email between servers and does not collect system performance data.
  4. DFTP transfers files and is not designed to monitor or manage device performance.
T-15

A host at 10.1.1.50 returns different identifiers: SNMP sysName="srv-db-01", NetBIOS name="FILESERVER", LDAP CN="webserver", and Nmap PTR="mail.internal.local". How should the analyst determine whether these records represent one system or multiple systems?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADiscarding data throws away evidence; each protocol reflects a different naming source, and one protocol alone would hide the discrepancy.
  2. BDifferent names from different protocols are common on a single host, so declaring an IP conflict without evidence is premature.
  3. CCorrect: matching MAC address, service fingerprints and timestamps, then checking for aliases or stale DNS and directory entries, determines whether one host has several names.
  4. DReverse DNS is often stale or misconfigured, so treating it as authoritative while ignoring the other sources is unjustified.
T-16

What is the MOST efficient multi-step Nmap workflow to thoroughly enumerate unknown web application services on a target network while minimizing false positives and avoiding excessive scan aggression?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: identifying services and versions first lets you then run only the scripts relevant to those web services, reducing noise and false positives.
  2. BRunning vulnerability sweeps before even knowing the services is aggressive and produces noisy, poorly targeted results.
  3. CRunning scripts before knowing which hosts are live reverses the logical order and wastes probes.
  4. DAggressive scanning first raises detection and outage risk, and OS fingerprinting does not enumerate web applications.
T-17

During a penetration test, you receive conflicting OS version data from a target's Nmap banner grab. How should you increase your confidence in identifying the correct operating system version?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATCP stack fingerprinting is useful but can be confused by firewalls, load balancers or tuned stacks, so relying on it alone keeps the uncertainty.
  2. BA banner is configurable and may be stale or deliberately misleading, so trusting it completely ignores the conflict.
  3. CCorrect: SNMP system descriptions, SMB OS discovery and LDAP directory attributes are independent sources that can confirm or refute the OS version.
  4. DMore aggressive port sweeps add noise and risk but do not provide better evidence about the operating system version.

Enumeration points people miss

How is enumeration different from scanning?

Scanning finds open ports and services; enumeration queries those services to extract usernames, shares and configuration. It is more intrusive and far more likely to be logged.

What should I study after this module?

Vulnerability analysis, which turns the services and versions you enumerated into scored, prioritized weaknesses.

Sources