CEH Enumeration and System Hacking Practice Question
Which TWO of the following are enumeration techniques?
⚠ Common exam trap
EC-Council often tests the distinction between enumeration (passive or active information gathering) and exploitation (active attacks that compromise systems), so candidates mistakenly classify buffer overflow, XSS, or SQL injection as enumeration techniques when they are actually attack vectors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LDAP enumeration
LDAP enumeration (C) is a valid enumeration technique because it queries directory services on port 389 (or 636 for LDAPS) to extract information such as user accounts, group memberships, and organizational structure via anonymous or authenticated binds. SMTP enumeration (E) is also a valid enumeration technique, using commands like VRFY, EXPN, and RCPT TO to discover valid email addresses and usernames on a mail server. Both techniques focus on gathering information about a target rather than exploiting it. In contrast, buffer overflow (A), cross-site scripting (B), and SQL injection (D) are exploitation or attack techniques that compromise or manipulate a system, not enumeration methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Buffer overflow
Why it's wrong here
Buffer overflow is an exploitation technique where an attacker sends more data than a buffer can hold, overwriting adjacent memory locations. This can lead to crashing the program, altering program flow, or executing arbitrary code with elevated privileges. It is a method of gaining control over a system or application, rather than a process of discovering information about network resources or user accounts. Therefore, it falls under the exploitation phase of a penetration test, not enumeration.
- ✗
Cross-site scripting
Why it's wrong here
Cross-site scripting (XSS) is a client-side code injection attack where malicious scripts are injected into trusted websites. These scripts are then executed by the victim's browser, allowing attackers to bypass access controls, steal session cookies, deface websites, or redirect users to malicious sites. While it involves data manipulation, XSS is primarily focused on exploiting vulnerabilities in web applications to compromise user sessions or deliver malware, not on systematically discovering network services, user accounts, or system configurations.
- ✓
LDAP enumeration
Why this is correct
LDAP enumeration is a technique used to query Lightweight Directory Access Protocol (LDAP) services to extract detailed information about an organization's directory structure. This process can reveal valid usernames, group memberships, organizational units, and even password policies by sending specific queries to the LDAP server. Attackers leverage this information to map out the internal network, identify potential targets for credential stuffing, or understand the hierarchy for privilege escalation attempts. It is a critical step in gathering intelligence about user and system resources.
- ✗
SQL injection
Why it's wrong here
SQL injection is a code injection technique that exploits vulnerabilities in web applications by inserting malicious SQL statements into input fields. This allows attackers to interfere with the queries an application makes to its database, potentially bypassing authentication, retrieving sensitive data, modifying database contents, or even executing operating system commands. While data extraction can occur, the primary purpose of SQL injection is to manipulate database operations for unauthorized access or data compromise, making it an exploitation technique rather than a systematic discovery of network services or user accounts.
- ✓
SMTP enumeration
Why this is correct
SMTP enumeration involves using standard Simple Mail Transfer Protocol (SMTP) commands to discover valid user accounts on a mail server. Commands such as VRFY (verify), EXPN (expand), and RCPT TO (recipient to) can be leveraged to confirm the existence of specific usernames or mailing lists. A positive response indicates a valid account, providing attackers with a list of potential targets for brute-force attacks, phishing campaigns, or further information gathering. This direct querying of the mail server for user information is a classic enumeration technique.
Go deeper
Related to this question
Learn chapter
SQL Injection
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
Key term
LDAP Enumeration
LDAP Enumeration is the process of querying a Lightweight Directory Access Protocol server to gather information about users, groups, computers, and other network resources in an organization.
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.