GCIH SMB Security Practice Question
Why is it dangerous to leave port 445 open to the public internet on a Windows server?
⚠ Common exam trap
Students often assume port 445 exposure is only dangerous because of data interception, overlooking the severe risk of direct remote code execution and brute-forcing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It increases the attack surface for remote exploitation and credential brute-forcing.
Exposing port 445 to the internet allows any attacker globally to attempt to connect to the server's SMB service. SMB was never designed for internet exposure and contains numerous vulnerabilities that can be exploited remotely. Attackers use this access to perform reconnaissance, brute-force weak credentials, and deploy ransomware by exploiting unpatched vulnerabilities, making it one of the most critical firewall misconfigurations for any organization to avoid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It enables legitimate remote file access for all employees.
Why it's wrong here
While it technically allows remote access, it does so insecurely by exposing the protocol directly to the internet. Legitimate remote access should be handled via encrypted VPNs or secure gateways, never by opening SMB ports, which are inherently prone to exploitation and provide too much information to potential attackers.
- ✓
It increases the attack surface for remote exploitation and credential brute-forcing.
Why this is correct
Publicly exposing SMB makes the server a target for automated scanning and exploitation. Attackers can attempt to brute-force usernames and passwords or use known exploits to gain unauthorized access. Given the history of SMB vulnerabilities, this is an extremely high-risk practice that invites compromise from global threat actors.
- ✗
It forces the server to use SMBv1, which is faster for internet traffic.
Why it's wrong here
SMBv1 is not optimized for internet traffic and is dangerously insecure. Performance is not a valid justification for leaving port 445 open, as modern protocols and VPN solutions provide much better performance and security. Claiming it is 'faster' ignores the massive security risks associated with protocol-level vulnerabilities.
- ✗
It prevents the server from using internal authentication protocols.
Why it's wrong here
Exposing port 445 has no impact on internal authentication protocols. Authentication continues to function as configured; the risk is that the authentication interface is now accessible to the entire internet, which allows attackers to attempt to authenticate from outside the organization, directly bypassing internal network security controls.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.