GCIH SMB Security Practice Question
Which THREE actions are recommended to secure SMB against credential relay and man-in-the-middle attacks?
⚠ Common exam trap
Candidates frequently choose 'disabling SMB' as a whole. Disabling the entire protocol is usually not feasible in production; the correct approach is hardening it by disabling legacy versions and enforcing security flags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce SMB message signing
Securing SMB requires a layered approach focusing on authentication integrity and protocol restrictions. Enabling SMB signing ensures that packets are not modified in transit, while SMB encryption provides confidentiality. Furthermore, disabling legacy protocols like SMBv1 eliminates the weakest links that are often targeted for relaying. These steps are fundamental for hardening Windows environments against attackers aiming to steal or reuse credentials within the network, significantly hindering lateral movement and privilege escalation attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enforce SMB message signing
Why this is correct
SMB signing adds a cryptographic signature to each packet, ensuring that the traffic has not been modified in transit. This is a primary defense against man-in-the-middle attacks, as an attacker cannot forge or alter packets without the server detecting the invalid signature, effectively neutralizing the relay attack vector.
- ✗
Force the use of SMBv1 exclusively
Why it's wrong here
Forcing SMBv1 is the opposite of a secure configuration, as the protocol is inherently flawed and vulnerable to well-known exploits. It lacks the modern security features required to prevent relay attacks, making it a critical security risk that should be removed from all modern enterprise infrastructures immediately.
- ✓
Implement SMB encryption
Why this is correct
SMB encryption, introduced in newer versions of the protocol, ensures that sensitive data is protected from eavesdropping. Beyond confidentiality, it forces a secure channel that is inherently more resistant to tampering than plaintext SMB sessions, providing an essential layer of security for traffic traversing across untrusted or sensitive network segments.
- ✓
Disable the SMBv1 protocol
Why this is correct
Disabling SMBv1 removes the primary attack vector for many legacy exploits and relay-based attacks. By forcing clients and servers to use newer, more secure versions like SMBv3, organizations benefit from improved authentication mechanisms and encryption, which significantly reduces the potential for unauthorized access and lateral movement by malicious actors.
- ✗
Use cleartext passwords for SMB shares
Why it's wrong here
Using cleartext passwords is a severe security failure that allows attackers to easily capture credentials off the wire. SMB should always use secure, hashed authentication protocols, and the transport layer must be protected against interception to prevent credential theft and unauthorized access to shared resources within the network environment.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.