Certified Ethical Hacker (CEH) Practice Question

During a penetration test you established a null session to a Windows Server 2016 domain controller and enumerated the list of users with the command rpcclient -U "". In the after-action meeting, the system administrator asks how to block this technique while still permitting legitimate SMB file sharing. Which single configuration change is the most effective countermeasure?

  • Set the registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous to 2 to block anonymous SID-to-name translation.

  • Disable NetBIOS over TCP/IP on all domain controller network interfaces.

  • Implement an account lockout policy that disables an account after three failed logon attempts.

  • Enable mandatory SMB packet signing on the domain controller.

Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot