Courseiva
SMB Security →mediumMultiple Select

GCIH SMB Security Practice Question

An incident responder is investigating a suspected SMB relay attack on a corporate network. The attacker has compromised a workstation and is attempting to relay authentication to a domain controller. Which TWO of the following conditions are necessary for a successful SMB relay attack? (Choose two.)

⚠ Common exam trap

The trap here is thinking that SMB relay requires the attacker to have credentials; in reality, the attacker relays the victim's authentication, so no credentials are needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SMB signing must be disabled or not required on the target server.

The correct answers are that SMB signing must be disabled or not required on the target server, and the victim's NTLM authentication must be relayed to a server that accepts NTLM. These conditions allow the attacker to forward authentication without detection. The other options are not necessary: valid credentials are not needed, physical access is not required, and SMB 1.0 is not a prerequisite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SMB signing must be disabled or not required on the target server.

    Why this is correct

    SMB signing ensures the integrity and authenticity of SMB communications. If signing is disabled or not required, an attacker can modify and relay authentication messages without detection. This is a critical condition for SMB relay, as signing would prevent the relay by invalidating the tampered authentication.

  • ✗

    The target server must be running SMB 1.0.

    Why it's wrong here

    SMB relay can occur over SMB 2.x and 3.x as well, as long as NTLM authentication is used and signing is not enforced. SMB 1.0 is not a requirement; in fact, modern environments often use SMB 2/3, and relay attacks still work if signing is disabled.

  • ✗

    The attacker must have valid domain credentials for the target server.

    Why it's wrong here

    The attacker does not need valid credentials; the whole point of SMB relay is to relay the victim's authentication to the target. The attacker uses the victim's credentials implicitly through the relay. Requiring valid credentials would defeat the purpose of the attack.

  • ✗

    The attacker must have physical access to the victim's workstation.

    Why it's wrong here

    Physical access is not required for SMB relay. The attacker can compromise a workstation remotely and use techniques like ARP poisoning or DNS spoofing to intercept authentication attempts. Physical access might facilitate other attacks but is not a necessary condition for relay.

  • ✓

    The victim's NTLM authentication must be relayed to a server that accepts NTLM authentication.

    Why this is correct

    SMB relay works by forwarding the victim's NTLM authentication messages to a target server that accepts NTLM. If the target only accepts Kerberos or has NTLM disabled, the relay will fail. Thus, the target must support NTLM authentication for the relay to succeed.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.