Courseiva

CEH Enumeration and System Hacking Practice Question

A system administrator wants to enumerate all users in an Active Directory domain. Which protocol and query technique should they use?

⚠ Common exam trap

A common mix-up: candidates confuse SMB null sessions (a deprecated attack) with LDAP anonymous queries (a current, often-valid technique), or they mistakenly think SMTP VRFY is relevant to domain user enumeration instead of email address verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

LDAP anonymous query

LDAP anonymous queries allow unauthenticated users to query an Active Directory domain for directory information, including user enumeration. While modern Active Directory configurations often restrict anonymous LDAP binds by default for security reasons, if enabled or misconfigured, it becomes a highly effective technique for enumerating users without credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SNMP with public community string

    Why it's wrong here

    SNMP (Simple Network Management Protocol) is primarily used for monitoring and managing network devices, servers, and other IP-enabled equipment. While it can reveal system information like running processes, network interfaces, and installed software via Management Information Bases (MIBs), it does not directly query or enumerate Active Directory user accounts. Therefore, it is not an effective method for listing AD users.

  • ✗

    SMB null session

    Why it's wrong here

    An SMB (Server Message Block) null session involves connecting to a Windows server without authentication, often using the IPC$ share. Historically, this vulnerability allowed attackers to enumerate local user accounts, shares, and even some domain users from older Windows NT domains or standalone servers by querying the Security Account Manager (SAM) database. However, modern Active Directory environments and Windows server configurations typically restrict null session access to prevent such enumeration, making it an unreliable method for comprehensively listing AD users.

  • ✗

    SMTP VRFY

    Why it's wrong here

    The SMTP (Simple Mail Transfer Protocol) VRFY command is designed to verify the existence of a specific email address on a mail server. When a client sends a VRFY command with an email address, the mail server responds indicating whether that address is valid or not. While this can confirm the existence of *email-enabled* users, it does not provide a comprehensive list of all Active Directory users, nor does it directly query the directory service itself.

  • ✓

    LDAP anonymous query

    Why this is correct

    LDAP (Lightweight Directory Access Protocol) is the primary protocol for querying and modifying directory services, including Microsoft Active Directory. An anonymous LDAP query attempts to bind to the directory without providing any credentials. If the Active Directory server is misconfigured to allow anonymous binds and access to user objects, an attacker can enumerate a significant amount of user information, including usernames, email addresses, and other attributes, making it a highly effective method for user enumeration.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.