CEH Vulnerability Analysis and System Hacking Practice Question
An ethical hacker is performing a vulnerability scan against a Windows Server 2019 host using Nessus. The scan returns a finding titled 'Microsoft Windows SMB Registry Remotely Accessible' with a CVSS base score of 5.0. The report marks the vulnerability as 'Medium' severity but does not provide a specific patch. Which of the following should the tester do NEXT to determine the actual risk and remediation?
⚠ Common exam trap
The trap here is assuming a medium CVSS score means the finding can be ignored or that exploitation is the only way to validate it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate the finding with the Microsoft Security Response Center (MSRC) advisory and verify the registry key exposure with a manual check.
A scanner finding without a specific patch requires validation against vendor advisories and manual confirmation. Correlating with MSRC advisories and checking the registry key manually establishes whether the exposure is real and what patch applies. This avoids false positives and provides precise remediation, which is essential in vulnerability analysis before any exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full credential brute-force attack against SMB to see if the registry can be accessed.
Why it's wrong here
Brute-forcing credentials is an intrusive action that can lock accounts and trigger alarms. It does not directly verify the registry exposure and may violate the rules of engagement. The finding concerns remote registry access permissions, not password strength, so this approach is misaligned with the vulnerability's nature and remediation path.
- ✓
Correlate the finding with the Microsoft Security Response Center (MSRC) advisory and verify the registry key exposure with a manual check.
Why this is correct
This is correct because a scanner's generic finding often lacks patch-level detail. Correlating with MSRC advisories and manually verifying the exposed registry key confirms whether the issue is truly exploitable and identifies the precise patch. This reduces false positives and gives the client actionable remediation guidance, which is the core of vulnerability analysis.
- ✗
Immediately exploit the SMB registry exposure using Metasploit to prove impact before reporting.
Why it's wrong here
Exploiting without confirmation can cause service disruption and exceeds the engagement scope if not explicitly authorized. The finding may be a false positive or informational, so weaponizing it prematurely risks system stability and legal boundaries. The ethical approach is to validate via non-intrusive means first, then exploit only if rules of engagement permit and risk is confirmed.
- ✗
Mark the finding as a false positive because CVSS 5.0 is not critical and ignore it.
Why it's wrong here
CVSS 5.0 still represents a medium-severity issue that may chain with other weaknesses. Dismissing it without validation can leave an exploitable path for lateral movement or credential theft. A tester must investigate rather than assume a false positive based solely on score, since context such as network exposure can elevate real risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.