米国に拠点を置く小売企業への侵入テスト中、ジョンは構造化クエリに対して異常な応答をするセカンダリサーバーへのアクセスに成功しました。特別に細工されたリクエストを送信することで、対象組織に属するサブドメイン、MXレコード、エイリアスの完全なリストを取得しました。このレスポンスには、さらなる攻撃に悪用される可能性のある機密性の高い内部マッピング情報が含まれていました。
この列挙を実行するために使用された可能性が最も高いツールはどれですか?
正解:D
The most likely tool/command is dig @server axfr, which attempts a DNS zone transfer (AXFR) from a specified DNS server. In CEH-aligned reconnaissance and enumeration methodology, DNS is a high-value target because it reveals how an organization's names map to systems. A successful zone transfer can expose an entire DNS zone database, often including hostnames (subdomains), mail exchanger (MX) records, canonical name (CNAME) aliases, and sometimes internal-facing entries if the zone is misconfigured. The scenario's outcome-receiving "a full list of subdomains, MX records, and aliases"-matches exactly what an AXFR zone transfer can disclose when a DNS server is improperly configured to allow transfers to unauthorized hosts.
The clue about a "secondary server" is also significant. In DNS architecture, organizations frequently deploy primary (master) and secondary (slave) DNS servers. Secondary servers legitimately request zone transfers from the master to stay synchronized. If the secondary server is misconfigured (for example, allowing AXFR to any requester or to a broader range than intended), an attacker can exploit this and retrieve the zone file.
This results in detailed visibility into the organization's naming scheme and infrastructure layout- information that can be used to identify high-value targets (mail servers, VPN portals, admin hosts), locate staging points, and plan follow-on attacks such as credential harvesting, targeted exploitation, or social engineering.
Why the other options do not fit: smtp-user-enum.pl is used for enumerating valid users on SMTP servers, not DNS records. ldapsearch enumerates directory information from LDAP services, not DNS zones. nbtstat -A queries NetBIOS name tables for Windows hosts, which may reveal local names and shares but not DNS- wide subdomains and MX/CNAME records. Therefore, the enumeration described is most consistent with a DNS zone transfer using dig with AXFR.