試験312-50v13-JPN トピック1 問題1050 スレッド

ECCouncil 312-50v13-JPNのリアル試験問題集
問題 #: 1050
トピック #: 1
地方の小売企業のデジタルインフラの外部評価において、セキュリティアナリストのジョーは、能動的な侵入を伴わずに内部サービスのマッピングを行う任務を負いました。公開されている解決システムの動作をテストしていたジョーは、あるセカンダリシステムが構造化クエリに対して異常な応答をすることを発見しました。特定の形式のリクエストを発行すると、サーバーは認証情報の入力を要求したりアラートをトリガーしたりすることなく、サブドメイン、メールホスト、システムエイリアスを含む内部マッピングの完全なリストを応答しました。
この情報を取得するために使用された可能性が最も高い手法はどれですか?

おすすめの解答:C 解答を投票する

The described behavior matches DNS Zone Transfer Enumeration. In CEH reconnaissance, DNS enumeration aims to discover hosts and services by querying DNS records. A zone transfer is a special DNS operation intended for legitimate replication between an authoritative primary DNS server and its secondary DNS servers. When misconfigured, a DNS server may allow an unauthorized requester to perform a zone transfer, returning the entire DNS zone database. This can reveal extensive internal naming information such as subdomains, hostnames, mail exchangers, service records, and aliases, exactly like the "full list of internal mappings, including subdomains, mail hosts, and system aliases" described in the question. The clue
"secondary system responds unusually" is especially telling, because secondary DNS servers are commonly the ones configured for replication and may be mistakenly left open to transfers from any host.
The other options do not fit the output. LDAP enumeration targets directory services and would not yield DNS-style mappings unless you already had directory access and queries. NTP enumeration relates to time synchronization services and can reveal time/server details, not comprehensive host/subdomain lists.
NetBIOS enumeration focuses on Windows networking (names, shares, workgroups) typically on internal networks and would not produce a DNS zone's record set.
CEH-recommended mitigations include restricting zone transfers to authorized secondary server IPs only, using TSIG keys for authenticated transfers, minimizing publicly exposed DNS data, splitting internal and external DNS (split-horizon), and continuously auditing DNS configurations to prevent inadvertent information leakage.

Yasuhara 2026-07-21 11:29:40

コメント

正解:
?」こちらは投票コメントになっております。普通のコメントに切り替えます。
ニックネーム: 送信 キャンセル
投票コメントをあげるごとに、選択した解答の投票数を1つ増やすことができます。

他人の解答コメントを賛成するのも、その解答に一票を入れることになります。したがって、すでに同じ意見の投票コメントが存在する場合、新規コメントをする代わりに賛成することもできます。

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡