GCIH Attacking Passwords Practice Question
During an incident response engagement, you capture SMB authentication traffic on a subnet where an attacker has positioned a rogue device. The traffic shows NTLMv2 challenge/response pairs being relayed to a file server that does not enforce SMB signing. Which of the following best describes the security control that would have most directly prevented the relayed authentication from succeeding?
⚠ Common exam trap
The trap here is assuming that requiring Kerberos or disabling NetBIOS eliminates NTLM relay, when NTLM fallback over SMB remains viable unless SMB signing is enforced.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforcing SMB signing on the target file server
SMB signing is the specific control that prevents NTLM relay to SMB file servers because it requires the client and server to sign every message with a session key. A relayed authentication cannot satisfy signing because the attacker does not possess the negotiated session key. Other controls like disabling NetBIOS or requiring Kerberos do not address the fundamental relay path over SMB.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enabling Extended Protection for Authentication on the domain controller
Why it's wrong here
Extended Protection for Authentication (EPA) binds authentication to the TLS channel or SPN and is effective for HTTP-based services like Exchange and LDAP over TLS. It does not apply to native SMB file server sessions, so enabling EPA on a domain controller would not prevent the relayed NTLM authentication to the file server in this scenario.
- ✓
Enforcing SMB signing on the target file server
Why this is correct
SMB signing cryptographically binds each message to the session key derived from the authentication exchange, so a relayed authentication cannot be reused to establish a new session. When the file server requires signing and the client cannot sign, the session fails. This directly breaks the NTLM relay because the attacker cannot produce valid signatures without possessing the session key.
- ✗
Disabling NetBIOS over TCP/IP on all workstations
Why it's wrong here
Disabling NetBIOS over TCP/IP reduces legacy name resolution and some broadcast-based poisoning opportunities, but it does not stop NTLM relay over SMB, which operates on TCP port 445. The relayed authentication in this scenario flows directly to the file server over SMB, so removing NetBIOS does not invalidate the relayed challenge/response or prevent the session from being established.
- ✗
Requiring Kerberos authentication for all domain logons
Why it's wrong here
Kerberos is preferred for domain authentication, but NTLM remains enabled by default and can be used for SMB access to file servers even in a Kerberos-capable domain. Simply requiring Kerberos for logons does not prevent a client from falling back to NTLM for SMB, and the relayed NTLM authentication would still succeed unless signing or another NTLM-specific control is enforced.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.