GCIH SMB Security Practice Question
An analyst notices an increase in SMB authentication failures from a workstation. What is the most likely cause if the workstation has a stored credential that is being used for SMB connections?
⚠ Common exam trap
Candidates often suspect an active attack or a network issue, overlooking the most common cause: the Windows Credential Manager holding onto stale, cached credentials that conflict with updated domain passwords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The stored credential is out of sync with the current domain password.
Stored credentials in Windows Credential Manager can cause authentication failures if the password for the account has been changed in Active Directory but not updated in the local cache. When the system attempts to connect to an SMB share, it automatically uses the stale stored credential, leading to repeated failed attempts. This can lock out the user's account, making it a critical issue to address for operational continuity and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SMB server is blocking all incoming traffic.
Why it's wrong here
If the server were blocking all traffic, the connection would time out or be reset at the TCP level rather than showing authentication failures. The presence of authentication failures implies that the SMB handshake is occurring and the server is actively rejecting the credentials provided by the client's connection attempt.
- ✓
The stored credential is out of sync with the current domain password.
Why this is correct
When the domain password is changed, the local cached credential becomes invalid. The workstation continues to send the old password, resulting in authentication failures. This is a common support issue and a potential security concern, as it can lead to account lockouts and indicates that the workstation is misconfigured for current environment security.
- ✗
The SMBv1 protocol is disabled on the workstation.
Why it's wrong here
Disabling SMBv1 would cause connection failures if the server required it, but it would not specifically manifest as an 'authentication failure'. It would likely present as a 'connection refused' or 'protocol not supported' error. Authentication failures specifically point to incorrect or stale credentials provided during the security negotiation phase.
- ✗
The firewall is blocking port 445 on the workstation.
Why it's wrong here
Firewall blocks occur before the authentication process. If the firewall were blocking the connection, the system wouldn't reach the stage where it attempts to authenticate. The failure happens during the SMB session setup, proving that the network path is open but the provided credentials are being rejected by the server.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.