GCIH SMB Security Practice Question
Which TWO of the following steps are considered effective for hardening the SMB service against modern threats?
⚠ Common exam trap
Candidates often suggest 'disabling SMB' entirely. In a production environment, you cannot simply disable SMB; you must harden it by removing legacy versions and enforcing integrity via signing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require SMB signing for all connections
Hardening SMB involves a combination of removing legacy protocols and enforcing strong authentication and integrity controls. Disabling SMBv1 is the most critical step to prevent known exploits, while enforcing SMB signing provides the necessary protection against man-in-the-middle and relay attacks. Together, these measures significantly reduce the risk of lateral movement and unauthorized access, creating a much more resilient file-sharing environment that aligns with current security standards for enterprise networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require SMB signing for all connections
Why this is correct
SMB signing is essential to ensure that communication between the client and server has not been tampered with. Enforcing this prevents relay attacks, as the attacker cannot produce a valid signature for the packets. This is a fundamental security requirement in any modern, secure Windows network environment.
- ✗
Enable Guest Auth for compatibility
Why it's wrong here
Enabling guest authentication is a significant security risk that should be avoided. It allows unauthenticated connections, which can be exploited for data theft or lateral movement. Modern environments should rely on strictly authenticated access via established credentials, never permitting guest access to sensitive shares or network resources.
- ✓
Disable the SMBv1 protocol completely
Why this is correct
SMBv1 is an obsolete protocol that is riddled with security flaws, including the well-known EternalBlue vulnerability. Disabling it is a mandatory step in any hardening project, as it effectively removes the primary attack vector used by many worms and ransomware variants to spread throughout an internal network environment.
- ✗
Use the LanmanServer for internet access
Why it's wrong here
The LanmanServer service should never be exposed to the internet. SMB is intended for use within trusted internal networks. Exposing it to the internet provides a massive attack surface for global threat actors to exploit, leading to data breaches, ransomware infections, and full-scale compromise of the organization's server infrastructure.
- ✗
Disable all firewall logging on port 445
Why it's wrong here
Disabling logging is detrimental to incident response. Security teams need logs to identify unauthorized attempts to access SMB shares, brute-force activity, or lateral movement patterns. Keeping detailed firewall logs is vital for detecting attacks in progress and conducting forensic analysis after an incident occurs, making it a critical operational requirement.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.