Courseiva
SMB Security →hardMultiple Select

GCIH SMB Security Practice Question

Which THREE actions are recommended to secure SMB against credential relay and man-in-the-middle attacks?

⚠ Common exam trap

Candidates frequently choose 'disabling SMB' as a whole. Disabling the entire protocol is usually not feasible in production; the correct approach is hardening it by disabling legacy versions and enforcing security flags.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce SMB message signing

Securing SMB requires a layered approach focusing on authentication integrity and protocol restrictions. Enabling SMB signing ensures that packets are not modified in transit, while SMB encryption provides confidentiality. Furthermore, disabling legacy protocols like SMBv1 eliminates the weakest links that are often targeted for relaying. These steps are fundamental for hardening Windows environments against attackers aiming to steal or reuse credentials within the network, significantly hindering lateral movement and privilege escalation attempts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enforce SMB message signing

    Why this is correct

    SMB signing adds a cryptographic signature to each packet, ensuring that the traffic has not been modified in transit. This is a primary defense against man-in-the-middle attacks, as an attacker cannot forge or alter packets without the server detecting the invalid signature, effectively neutralizing the relay attack vector.

  • ✗

    Force the use of SMBv1 exclusively

    Why it's wrong here

    Forcing SMBv1 is the opposite of a secure configuration, as the protocol is inherently flawed and vulnerable to well-known exploits. It lacks the modern security features required to prevent relay attacks, making it a critical security risk that should be removed from all modern enterprise infrastructures immediately.

  • ✓

    Implement SMB encryption

    Why this is correct

    SMB encryption, introduced in newer versions of the protocol, ensures that sensitive data is protected from eavesdropping. Beyond confidentiality, it forces a secure channel that is inherently more resistant to tampering than plaintext SMB sessions, providing an essential layer of security for traffic traversing across untrusted or sensitive network segments.

  • ✓

    Disable the SMBv1 protocol

    Why this is correct

    Disabling SMBv1 removes the primary attack vector for many legacy exploits and relay-based attacks. By forcing clients and servers to use newer, more secure versions like SMBv3, organizations benefit from improved authentication mechanisms and encryption, which significantly reduces the potential for unauthorized access and lateral movement by malicious actors.

  • ✗

    Use cleartext passwords for SMB shares

    Why it's wrong here

    Using cleartext passwords is a severe security failure that allows attackers to easily capture credentials off the wire. SMB should always use secure, hashed authentication protocols, and the transport layer must be protected against interception to prevent credential theft and unauthorized access to shared resources within the network environment.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.