Courseiva
SMB Security →mediumMultiple Select

GCIH SMB Security Practice Question

Which TWO of the following are primary security risks associated with the SMBv1 protocol in a modern Windows environment?

⚠ Common exam trap

Candidates often focus on data loss or unauthorized access, missing the specific technical vulnerabilities like RCE (EternalBlue) and MITM that make SMBv1 uniquely dangerous compared to newer protocol versions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Susceptibility to remote code execution via EternalBlue

SMBv1 is an archaic protocol that lacks modern security features, making it a critical target for attackers. Its primary risks include vulnerability to well-known remote code execution exploits like EternalBlue and its susceptibility to man-in-the-middle attacks due to weak or absent integrity checks. Understanding these risks is vital for incident handlers to prioritize the deprecation of legacy protocols, which are often the primary entry points for ransomware and lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inability to support Kerberos authentication

    Why it's wrong here

    SMBv1 does support various authentication mechanisms, including NTLM and Kerberos. The risk is not the lack of Kerberos support, but rather the underlying protocol design that allows for packet manipulation and session hijacking, regardless of the authentication method used during the initial setup of the SMB connection.

  • ✓

    Susceptibility to remote code execution via EternalBlue

    Why this is correct

    SMBv1 was the vector for the infamous EternalBlue exploit, which allowed attackers to execute code remotely on vulnerable systems. This vulnerability remains a primary reason why security professionals advocate for the total removal of SMBv1, as it provides a reliable path for attackers to gain administrative control over systems.

  • ✗

    Lack of support for SMB message signing

    Why it's wrong here

    SMBv1 does technically support message signing, but it is rarely enforced by default and is often ignored or disabled in legacy environments. The actual risk lies in the protocol's inherent design flaws and its historical tendency to facilitate relay attacks rather than a total absence of signing functionality.

  • ✓

    Increased risk of man-in-the-middle and relay attacks

    Why this is correct

    SMBv1 is notoriously easy to exploit via relay attacks when signing is not strictly enforced. Attackers can intercept traffic, perform session hijacking, or relay authentication tokens to other resources on the network. This makes SMBv1 a major liability in any environment where network integrity and confidentiality are required.

  • ✗

    Incompatibility with NTFS permissions

    Why it's wrong here

    SMBv1 is fully compatible with NTFS permissions and does not affect the underlying file system's access controls. The protocol is simply the transport mechanism used to interact with file shares; the issue is not its compatibility with file system permissions, but its intrinsic protocol-level security and architectural weaknesses.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.