Courseiva
SMB Security →easyMultiple Choice

GCIH SMB Security Practice Question

An incident handler is reviewing SMB traffic logs from a small business network and notices that a client successfully authenticated to the IPC$ share on a file server using a null session. The handler wants to explain to management why this is a security concern. Which of the following best describes the risk of a successful null session to IPC$?

⚠ Common exam trap

The trap here is equating null session access to IPC$ with full file share access or code execution, when the actual risk is unauthenticated information enumeration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It permits unauthenticated enumeration of users, groups, shares, and other system information.

A null session to IPC$ is an unauthenticated connection that allows limited queries through named pipes and RPC. Attackers use it to enumerate users, groups, shares, and domain information without credentials. This reconnaissance does not grant file access or code execution, but it exposes details that make later attacks easier. Restricting anonymous access and disabling null sessions reduces this information disclosure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It causes the server to disable SMB signing for all subsequent authenticated sessions.

    Why it's wrong here

    Null session access to IPC$ has no effect on SMB signing configuration. Signing is governed by server and client policy, not by whether an anonymous connection was made. A null session does not alter the security settings of later authenticated sessions. This option invents a relationship between anonymous enumeration and signing that does not exist in SMB behavior.

  • ✗

    It enables the client to execute arbitrary code on the server with SYSTEM privileges.

    Why it's wrong here

    A null session does not provide code execution or SYSTEM privileges. It is an unauthenticated connection that permits limited information queries, not remote command execution. While specific vulnerabilities in exposed services could be leveraged after enumeration, the null session itself is not a code execution primitive. Claiming SYSTEM-level execution greatly exaggerates the direct risk of the null session.

  • ✓

    It permits unauthenticated enumeration of users, groups, shares, and other system information.

    Why this is correct

    A null session to IPC$ allows an unauthenticated client to query certain system information through named pipes and RPC, such as user and group lists, share names, and domain details. This reconnaissance helps an attacker map the environment and plan further attacks. It does not grant file access, but the information disclosure is significant because it lowers the effort needed for lateral movement and privilege escalation.

  • ✗

    It allows the client to read and write files in all shared folders on the server.

    Why it's wrong here

    A null session to IPC$ does not grant file read or write access to shared folders. IPC$ is a special inter-process communication share used for named pipes and RPC, not for general file storage. File shares have their own access controls that a null session does not bypass. Confusing IPC$ access with full file share access overstates the immediate impact and misdirects remediation.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.