Certified Ethical Hacker CEH · Free Practice Question Medium

Question 44

A vulnerability scan has returned the following results:

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- 
Detailed Results 
10.56.17.21 (APACHE-2.4)   
Windows Shares 

Category: Windows 
CVE ID: - 
Vendor Ref: - 
Bugtraq ID: - 
Service Modified - 8.30.2017   

Enumeration Results: 
print$ c:\windows\system32\spool\drivers 
files c:\FileShare\Accounting   
Temp c:\temp
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

What best describes the meaning of this output?

  • A There is an unknown bug in an Apache server with no Bugtraq ID
  • B Connecting to the host using a null session allows enumeration of the share names on the host
  • C Windows Defender has a known exploit that must be resolved or patched
  • D There is no CVE present, so this is a false positive caused by Apache running on a Windows server
Reveal correct answer

Correct answer: B

Explanation

OBJ-3.1: These results from the vulnerability scan conducted shows an enumeration of open Windows shares on an Apache server. The enumeration results show three share names (print$, files, Temp) were found using a null session connection. There is no associated CVE with this vulnerability, but it is not a false positive. Not all vulnerabilities have a CVE associated with them. Nothing in this output indicates anything concerning Windows Defender, so this is not the correct answer. Bugtraq IDs are a different type of identification number issued for vulnerabilities by SecurityFocus. Generally, if there is a CVE, there will also be a Bugtraq ID. Both the CVE and Bugtraq ID being blank is not suspicious since we are dealing with a null enumeration result.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need