Courseiva
SMB Security →mediumMultiple Select

GCIH SMB Security Practice Question

Which TWO of the following steps are considered effective for hardening the SMB service against modern threats?

⚠ Common exam trap

Candidates often suggest 'disabling SMB' entirely. In a production environment, you cannot simply disable SMB; you must harden it by removing legacy versions and enforcing integrity via signing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require SMB signing for all connections

Hardening SMB involves a combination of removing legacy protocols and enforcing strong authentication and integrity controls. Disabling SMBv1 is the most critical step to prevent known exploits, while enforcing SMB signing provides the necessary protection against man-in-the-middle and relay attacks. Together, these measures significantly reduce the risk of lateral movement and unauthorized access, creating a much more resilient file-sharing environment that aligns with current security standards for enterprise networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Require SMB signing for all connections

    Why this is correct

    SMB signing is essential to ensure that communication between the client and server has not been tampered with. Enforcing this prevents relay attacks, as the attacker cannot produce a valid signature for the packets. This is a fundamental security requirement in any modern, secure Windows network environment.

  • ✗

    Enable Guest Auth for compatibility

    Why it's wrong here

    Enabling guest authentication is a significant security risk that should be avoided. It allows unauthenticated connections, which can be exploited for data theft or lateral movement. Modern environments should rely on strictly authenticated access via established credentials, never permitting guest access to sensitive shares or network resources.

  • ✓

    Disable the SMBv1 protocol completely

    Why this is correct

    SMBv1 is an obsolete protocol that is riddled with security flaws, including the well-known EternalBlue vulnerability. Disabling it is a mandatory step in any hardening project, as it effectively removes the primary attack vector used by many worms and ransomware variants to spread throughout an internal network environment.

  • ✗

    Use the LanmanServer for internet access

    Why it's wrong here

    The LanmanServer service should never be exposed to the internet. SMB is intended for use within trusted internal networks. Exposing it to the internet provides a massive attack surface for global threat actors to exploit, leading to data breaches, ransomware infections, and full-scale compromise of the organization's server infrastructure.

  • ✗

    Disable all firewall logging on port 445

    Why it's wrong here

    Disabling logging is detrimental to incident response. Security teams need logs to identify unauthorized attempts to access SMB shares, brute-force activity, or lateral movement patterns. Keeping detailed firewall logs is vital for detecting attacks in progress and conducting forensic analysis after an incident occurs, making it a critical operational requirement.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.