Courseiva
Active Directory Attacks →hardMultiple Choice

PEN-200 Active Directory Attacks Practice Question

Why does enabling 'SMB Signing' prevent NTLM relay attacks?

⚠ Common exam trap

Candidates often assume SMB signing encrypts the entire traffic flow. In reality, it only adds a cryptographic signature to each packet to verify its integrity and origin, preventing unauthorized relaying.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It validates the integrity of the authentication packets

SMB Signing adds a cryptographic signature to each packet in an SMB communication. When a relay attack occurs, the attacker does not possess the session key required to generate these signatures for the relayed packets. Consequently, the target server detects the missing or invalid signature and rejects the authentication attempt, effectively neutering the relay attack at the protocol level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It encrypts the entire SMB session using TLS

    Why it's wrong here

    SMB signing is distinct from SMB encryption. While encryption protects data confidentiality, signing specifically protects data integrity by using signatures. Signing alone does not provide encryption for the session, but it is sufficient to prevent relay attacks by ensuring that the packet stream cannot be intercepted and modified or relayed.

  • ✗

    It requires the client to prove they have the password

    Why it's wrong here

    SMB signing does not change the authentication requirement; it changes how the communication is validated after authentication. The client still performs the standard NTLM handshake. Signing adds a mandatory integrity check for subsequent communication packets, which the attacker cannot forge without the session key derived from the original authentication.

  • ✓

    It validates the integrity of the authentication packets

    Why this is correct

    SMB signing forces the use of cryptographic signatures for every packet. Because the attacker cannot generate valid signatures for the relayed authentication without the session key, the target server rejects the relayed packets. This makes it impossible to relay authentication successfully between a client and a target server.

  • ✗

    It disables NTLM authentication globally

    Why it's wrong here

    SMB signing does not disable NTLM authentication. It simply adds an integrity check to the SMB protocol. NTLM remains a valid authentication method, but its use is now protected by mandatory signatures, which prevents the specific vulnerability of relaying authentication attempts to unauthorized servers without the proper session keys.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.