A candidate must identify SMB attack paths and the right mitigation: disable SMBv1, block port 445 at the perimeter, enforce SMB signing to stop relay, and read SMB2 CREATE/WRITE traffic to spot mass file overwrite. Getting SMB signing and port 445 exposure right is most important.
Start practicing
SMB Security — choose a session length
Free · No account required
Domain overview
This domain covers Server Message Block as an attack surface and evidence source on Windows networks. GCIH questions test SMBv1 risk, port 445 exposure, SMB relay and signing, NTLM authentication coercion, and interpreting SMB2 CREATE/WRITE activity in incident response. Expect scenario-based items asking you to identify risks, attacker techniques, and the correct hardening or containment action.
Exam objectives
SMBv1 legacy protocol risks: EternalBlue/WannaCry exploitation, null sessions, no pre-auth integrity
Port 445 exposure to the internet enabling ransomware, worms, and brute-force or relay attacks
SMB relay and NTLM authentication: why SMB signing and disabling NTLMv1 mitigate relay to domain controllers
Analyzing SMB2 CREATE and WRITE requests in Wireshark to detect mass file overwrite or encryption activity
Assuming SMB signing is enabled by default everywhere; it is required on domain controllers but often not on member servers or workstations, enabling relay.
Confusing SMBv1 with SMBv2/3 and thinking disabling SMBv1 alone stops relay or ransomware; signing and port filtering are also needed.
Treating port 445 as internal-only and ignoring firewall rules that expose it; public 445 is a top ransomware and worm vector.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An incident handler observes that an internal server is leaking sensitive file system structure via SMB. Which configuration change most effectively prevents SMB null session enumeration?
2Which TWO of the following are primary security risks associated with the SMBv1 protocol in a modern Windows environment?
3An organization experiences a rapid spread of ransomware across the internal network. Analysts determine that the ransomware is exploiting SMB to move laterally. Which configuration effectively limits this spread by preventing SMB communication between workstations?
4Which THREE actions are recommended to secure SMB against credential relay and man-in-the-middle attacks?
5What is the primary function of SMB (Server Message Block) in a Windows network environment?
6Which security principle is most directly violated when an organization allows guest access to sensitive SMB file shares?
7Why is it dangerous to leave port 445 open to the public internet on a Windows server?
8During an incident response, you identify that an attacker is using an SMB relay attack to gain domain-level access. Which mitigation strategy effectively prevents this by forcing authentication through a secure, encrypted channel?
9Which of the following describes the purpose of the 'SMB Null Session' vulnerability?
10An analyst notices an increase in SMB authentication failures from a workstation. What is the most likely cause if the workstation has a stored credential that is being used for SMB connections?
11Which TWO of the following steps are considered effective for hardening the SMB service against modern threats?
12An incident handler is reviewing SMB traffic and notices multiple 'Tree Connect' requests to the IPC$ share. What does this activity typically signify in an attack scenario?
13An incident responder is analyzing a packet capture and observes a Windows workstation sending an SMB2 NEGOTIATE request listing only the SMB 2.0.2 dialect, followed by a SESSION_SETUP request containing an NTLMSSP Type 3 message. The server responds with STATUS_SUCCESS. The workstation normally communicates with this file server using SMB 3.1.1. What is the most likely explanation for this behavior?
14A security analyst is examining SMB traffic captured during an incident. The analyst observes a series of SMB2 Session Setup requests followed by Tree Connect requests to the IPC$ share, then attempts to access the srvsvc named pipe. The source IP is an internal workstation, and the destination is a domain controller. The workstation's user account is a standard domain user. Which of the following activities is the analyst MOST likely observing?
15An incident handler is reviewing SMB traffic and notices a large number of SMB2 CREATE requests for files with extensions like .docx, .xlsx, and .pdf, followed by SMB2 WRITE requests that overwrite the same files with encrypted content. The traffic originates from a single workstation and targets a file server. Which type of attack is most likely occurring?
16A healthcare organization's incident response team is investigating unusual SMB activity on a Windows file server. NetFlow data shows a single internal workstation opened SMB connections to more than 200 distinct hosts on TCP 445 within five minutes, and each connection lasted under two seconds. The workstation's user reports no unusual behavior. Which of the following is the most likely explanation for this traffic pattern?
17An incident responder is investigating a suspected SMB relay attack on a corporate network. The attacker has compromised a workstation and is attempting to relay authentication to a domain controller. Which TWO of the following conditions are necessary for a successful SMB relay attack? (Choose two.)
18An incident handler is investigating a suspected SMB relay attack at a financial services company. The team has captured traffic showing NTLM authentication being forwarded from a compromised workstation to a domain controller. Which two of the following controls would most directly mitigate this specific relay technique? (Choose two.)
19An incident handler is reviewing SMB traffic logs from a small business network and notices that a client successfully authenticated to the IPC$ share on a file server using a null session. The handler wants to explain to management why this is a security concern. Which of the following best describes the risk of a successful null session to IPC$?
20An incident responder is analyzing a memory dump from a compromised Windows workstation. The responder finds evidence of a tool that creates a named pipe and waits for a connection from a domain controller. The tool then relays authentication attempts to another server. Which of the following SMB-based attacks is the responder MOST likely investigating?
21During an incident investigation at a manufacturing firm, you capture SMB traffic on the internal network. You observe a workstation establishing an SMB2 session to a file server, and within the same TCP connection, the client sends a request to access the file share '\fileserver\Accounting' and then immediately sends a request to access the share '\fileserver\HR'. Both Tree Connect requests succeed and use the same SessionId. What does this activity most likely indicate?
A candidate must identify SMB attack paths and the right mitigation: disable SMBv1, block port 445 at the perimeter, enforce SMB signing to stop relay, and read SMB2 CREATE/WRITE traffic to spot mass file overwrite. Getting SMB signing and port 445 exposure right is most important.
The Courseiva GCIH question bank contains 21 questions in the SMB Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the SMB Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included