Courseiva
SMB Security →mediumMultiple Select

GCIH SMB Security Practice Question

An incident handler is investigating a suspected SMB relay attack at a financial services company. The team has captured traffic showing NTLM authentication being forwarded from a compromised workstation to a domain controller. Which two of the following controls would most directly mitigate this specific relay technique? (Choose two.)

⚠ Common exam trap

The trap here is choosing detection or password-hardening measures that improve visibility or credential strength but do not stop a real-time NTLM relay from being accepted by the target service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable NTLM authentication for all domain accounts and require Kerberos where possible.

NTLM relay succeeds because an attacker can forward a captured NTLM exchange to another service that accepts NTLM. Requiring SMB signing binds messages to the session and invalidates relayed authentication, while disabling NTLM and requiring Kerberos removes the reusable credential exchange entirely. Together these controls directly break the relay path, whereas password complexity, SMB1 enablement, and detection-only measures do not prevent the forwarded authentication from being accepted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disable NTLM authentication for all domain accounts and require Kerberos where possible.

    Why this is correct

    NTLM relay depends on NTLM challenge-response authentication being accepted. If NTLM is disabled and Kerberos is required, a captured NTLM exchange cannot be reused because the service will not accept NTLM credentials. This removes the underlying authentication mechanism the attacker relies on. It is a strong, direct mitigation for relay, though it requires careful compatibility planning.

  • ✓

    Enforce SMB signing on all SMB servers and clients via Group Policy.

    Why this is correct

    SMB signing cryptographically binds each SMB message to the session, so a relayed authentication cannot be used to establish a valid signed session with a different server. When signing is required on both ends, the attacker's forwarded NTLM exchange fails integrity checks. This directly breaks the relay path shown in the capture, making it a primary mitigation for SMB relay attacks.

  • ✗

    Enable SMB1 on all servers to improve compatibility with legacy clients.

    Why it's wrong here

    Enabling SMB1 increases the attack surface and does nothing to stop NTLM relay. SMB1 lacks modern security features and has known vulnerabilities, so reintroducing it would worsen the organization's exposure. Relay attacks can operate over SMB2 and SMB3 as well, so the protocol version alone is not the fix. This option moves in the opposite direction of mitigation.

  • ✗

    Require long, complex passwords for all domain users.

    Why it's wrong here

    Password complexity helps against offline cracking and credential guessing, but NTLM relay does not require the attacker to know or crack the password. The attacker forwards the victim's authentication exchange in real time, so a strong password does not prevent the relay from succeeding. This control is valuable for overall identity security but does not address the relay technique described.

  • ✗

    Deploy an intrusion detection system signature that alerts on SMB Tree Connect requests.

    Why it's wrong here

    Detection signatures can provide visibility into relay activity, but they do not mitigate or stop the attack. An alert on Tree Connect requests may be noisy and would not prevent the forwarded authentication from succeeding. The question asks for controls that directly mitigate the relay technique, so detection alone is insufficient. Prevention requires breaking the authentication path, not just observing it.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.