GCIH SMB Security Practice Question
Which TWO of the following are primary security risks associated with the SMBv1 protocol in a modern Windows environment?
⚠ Common exam trap
Candidates often focus on data loss or unauthorized access, missing the specific technical vulnerabilities like RCE (EternalBlue) and MITM that make SMBv1 uniquely dangerous compared to newer protocol versions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Susceptibility to remote code execution via EternalBlue
SMBv1 is an archaic protocol that lacks modern security features, making it a critical target for attackers. Its primary risks include vulnerability to well-known remote code execution exploits like EternalBlue and its susceptibility to man-in-the-middle attacks due to weak or absent integrity checks. Understanding these risks is vital for incident handlers to prioritize the deprecation of legacy protocols, which are often the primary entry points for ransomware and lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inability to support Kerberos authentication
Why it's wrong here
SMBv1 does support various authentication mechanisms, including NTLM and Kerberos. The risk is not the lack of Kerberos support, but rather the underlying protocol design that allows for packet manipulation and session hijacking, regardless of the authentication method used during the initial setup of the SMB connection.
- ✓
Susceptibility to remote code execution via EternalBlue
Why this is correct
SMBv1 was the vector for the infamous EternalBlue exploit, which allowed attackers to execute code remotely on vulnerable systems. This vulnerability remains a primary reason why security professionals advocate for the total removal of SMBv1, as it provides a reliable path for attackers to gain administrative control over systems.
- ✗
Lack of support for SMB message signing
Why it's wrong here
SMBv1 does technically support message signing, but it is rarely enforced by default and is often ignored or disabled in legacy environments. The actual risk lies in the protocol's inherent design flaws and its historical tendency to facilitate relay attacks rather than a total absence of signing functionality.
- ✓
Increased risk of man-in-the-middle and relay attacks
Why this is correct
SMBv1 is notoriously easy to exploit via relay attacks when signing is not strictly enforced. Attackers can intercept traffic, perform session hijacking, or relay authentication tokens to other resources on the network. This makes SMBv1 a major liability in any environment where network integrity and confidentiality are required.
- ✗
Incompatibility with NTFS permissions
Why it's wrong here
SMBv1 is fully compatible with NTFS permissions and does not affect the underlying file system's access controls. The protocol is simply the transport mechanism used to interact with file shares; the issue is not its compatibility with file system permissions, but its intrinsic protocol-level security and architectural weaknesses.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.