A penetration test identifies that an SMBv1 is enabled on multiple servers across an organization. The organization wants to remediate this vulnerability in the most efficient way possible. Which of the following should the organization use for this purpose?
Choose an answer
Tap an option to check your answer.
Correct answer: GPO.
Why this is the answer
Group Policy Objects (GPOs) are the most efficient way to disable SMBv1 across multiple servers in an organization. GPOs allow administrators to define and enforce security settings and configurations centrally for a large number of computers and users within an Active Directory domain. By creating a GPO that disables SMBv1 and linking it to the appropriate Organizational Units (OUs) containing the servers, the change can be applied uniformly and automatically. ACLs (Access Control Lists) control permissions for files and folders, not system-wide protocol settings. SFTP (SSH File Transfer Protocol) is a secure file transfer protocol and has no bearing on disabling SMBv1. DLP (Data Loss Prevention) solutions focus on preventing sensitive data from leaving the organization, not on configuring network protocols.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed