CEH Enumeration and System Hacking Practice Question
Which TWO of the following are valid enumeration techniques used to identify user accounts on a system? (Select 2)
⚠ Common exam trap
EC-CEH often tests the distinction between service discovery (e.g., port scanning) and actual user enumeration, leading candidates to mistakenly select nmap or DNS zone transfer as valid user enumeration techniques.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SMTP VRFY command
SMTP VRFY (option C) is a valid user-enumeration technique because the SMTP VRFY command asks the mail server to verify whether a given mailbox or username exists, and servers that respond with 250/251 confirm the account while 550 indicates it does not exist. SMB enumeration with enum4linux (option E) is also valid because it queries SMB/RPC services (such as SAMR and LSA) to extract usernames, groups, shares, and password policy information from Windows and Samba hosts. Port scanning with nmap (option A) only identifies open ports and services, not user accounts, so it is not an enumeration technique for accounts. A DNS zone transfer (option B) can reveal hostnames and subdomains but does not enumerate system user accounts. SNMPwalk of the entire MIB (option D) gathers device and system information via OIDs but does not directly enumerate user accounts on the target system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port scanning with nmap
Why it's wrong here
Nmap is primarily a network discovery and service identification tool, used to determine which hosts are active on a network and what services they are running by probing various ports. While it can identify open ports like 25 (SMTP) or 445 (SMB), its core functionality does not directly enumerate user accounts or credentials. It provides the initial reconnaissance necessary to identify potential services that could be enumerated, but it is not an enumeration technique for users itself.
- ✗
DNS zone transfer
Why it's wrong here
A DNS zone transfer (AXFR) is a legitimate mechanism for replicating DNS database files from a primary DNS server to a secondary server. If successful due to misconfiguration, it can reveal a comprehensive list of hostnames, IP addresses, and other resource records within a domain, mapping out network infrastructure. However, this process is designed to provide network topology information, not to directly list or enumerate individual user accounts or credentials within an organization.
- ✓
SMTP VRFY command
Why this is correct
The SMTP VRFY (Verify) command is a legacy feature of the Simple Mail Transfer Protocol used to confirm the existence of a specific user or mailbox on an SMTP server. An attacker can issue `VRFY username` to determine if a given username is valid, typically receiving a "250 OK" response for existing users or a "550 No such user" for non-existent ones. This direct query allows for effective enumeration of valid email addresses and associated user accounts.
- ✗
SNMPwalk of the entire MIB
Why it's wrong here
SNMPwalk is a utility that queries a network device using the Simple Network Management Protocol (SNMP) to retrieve a tree of information from its Management Information Base (MIB). It can gather extensive system details such as network interfaces, running processes, and system uptime, providing valuable configuration data. However, SNMPwalk does not inherently enumerate user accounts or credentials unless specific, non-standard MIB objects are populated with such sensitive information, which is generally considered a severe security misconfiguration.
- ✓
SMB enumeration using enum4linux
Why this is correct
Enum4linux is a specialized tool designed to enumerate information from Windows and Samba hosts by leveraging the Server Message Block (SMB) and Remote Procedure Call (RPC) protocols. It can extract a wealth of data, including lists of valid user accounts, group memberships, shared resources, and password policies. By utilizing various SMB/RPC functions like `NetUserEnum`, enum4linux directly facilitates the enumeration of user accounts on target systems, making it a highly effective technique.
Go deeper
Related to this question
Learn chapter
Scanning Networks
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
Key term
Nmap Scanning
Nmap scanning is a method used to discover devices running on a network and find open ports, services, and security weaknesses.
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.