Courseiva
SMB Security →mediumMultiple Choice

GCIH SMB Security Practice Question

An incident handler observes that an internal server is leaking sensitive file system structure via SMB. Which configuration change most effectively prevents SMB null session enumeration?

⚠ Common exam trap

Candidates often suggest disabling SMB entirely or using firewall rules, failing to recognize that the specific registry key 'RestrictAnonymous' is the standard, granular configuration to prevent null session enumeration on Windows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set RestrictAnonymous to 2

Disabling anonymous access and restricting null sessions is critical for hardening SMB. By configuring the RestrictAnonymous registry key to 2, the operating system denies all anonymous users from enumerating shares, usernames, and groups. This prevents attackers from performing reconnaissance against the server, significantly reducing the attack surface by ensuring that only authenticated users can query sensitive SMB metadata during the initial stages of a lateral movement attempt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set RestrictAnonymous to 0

    Why it's wrong here

    Setting this value to 0 allows anonymous users full access to perform enumeration tasks against the Security Account Manager database and share lists. This is the least secure configuration and directly facilitates reconnaissance activities by providing unauthenticated users with a detailed map of the system's shares and user accounts.

  • ✗

    Enable SMBv1 protocol support

    Why it's wrong here

    Enabling SMBv1 introduces severe security vulnerabilities, including susceptibility to EternalBlue-style exploits and legacy authentication flaws. This does nothing to restrict null session enumeration and instead provides attackers with a broader set of vectors to compromise the server, making it a highly dangerous configuration choice for any modern network.

  • ✓

    Set RestrictAnonymous to 2

    Why this is correct

    Setting this registry value to 2 enforces the highest level of restriction by preventing anonymous users from enumerating shares or user accounts. This forces the SMB service to require authenticated sessions for all enumeration requests, thereby effectively neutralizing standard null session reconnaissance techniques often used by attackers during internal network post-exploitation.

  • ✗

    Disable the LanmanServer service

    Why it's wrong here

    Disabling the entire LanmanServer service will stop the server from providing file and print sharing capabilities entirely. While this is secure, it is functionally disruptive and prevents legitimate business operations. A granular approach using registry keys allows security professionals to maintain functionality while disabling insecure features like null session support.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.