Courseiva
SMB Security →mediumMultiple Choice

GCIH SMB Security Practice Question

Which of the following describes the purpose of the 'SMB Null Session' vulnerability?

⚠ Common exam trap

Candidates often assume a null session is for data exfiltration, missing that its primary purpose in an attack lifecycle is reconnaissance—mapping the network and identifying targets before the actual exploitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To allow unauthenticated users to enumerate system information.

A null session occurs when a client connects to an SMB share without providing valid credentials. In older or misconfigured Windows systems, this allows anonymous users to query the server for sensitive information like user lists, group memberships, and share names. This information is vital for attackers during the reconnaissance phase, as it helps them map the environment and identify potential high-value targets for further exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To encrypt traffic between a client and a file server.

    Why it's wrong here

    Null sessions do the exact opposite of encryption; they provide unauthenticated access. They are a security vulnerability used for reconnaissance, not a mechanism to secure data in transit. Encryption is handled by SMB 3.0+ features, which are entirely separate from the concept of null sessions or anonymous connections.

  • ✓

    To allow unauthenticated users to enumerate system information.

    Why this is correct

    Null sessions allow anonymous users to query the server's Security Account Manager (SAM) and other internal databases. This provides attackers with a roadmap of the network, including usernames and shared resources, which they then use to craft targeted attacks, brute-force passwords, or plan lateral movement strategies throughout the enterprise.

  • ✗

    To bypass local firewall restrictions on port 445.

    Why it's wrong here

    Null sessions have nothing to do with firewall bypass. They are a feature of the SMB protocol's authentication negotiation. While they might be permitted by a firewall, they are a protocol-level capability, not a firewall-bypass technique. Confusing these concepts can lead to incorrect firewall rules that do not address the vulnerability.

  • ✗

    To prevent unauthorized access to sensitive file shares.

    Why it's wrong here

    Null sessions are a security weakness, not a protective mechanism. By allowing anonymous connections, they actively facilitate unauthorized access by removing the authentication barrier. Any configuration that enables null sessions is inherently insecure and must be remediated to ensure that only authenticated, authorized users can interact with the server's data.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.