From the approved test VLAN, a city domain controller still permits null-session enumeration of users and shares. What should the tester report?
Select an answer to reveal the explanation.
Short Explanation
A null session is like browsing the directory board in the lobby without signing in. Even without a badge, names and room lists can leak. That free intel feeds the next moves — shut it down where policy allows.
Full Explanation
Null or anonymous sessions against domain controllers or file services can still expose account lists, share names, and related metadata useful for planning. That disclosure is an enumeration finding, not proof of Domain Admin. Kerberos does not require leaving anonymous SMB/IPC exposure open for ticket renewal. CPTS reporting should flag the information leak and recommend hardening consistent with RoE and client policy.