You manage FileSrv1 (Windows Server 2022) hosting multiple SMB shares. For a share named Sensitive, you must ensure all SMB traffic is encrypted without affecting other shares. You must also prevent the use of SMBv1 on FileSrv1. What two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable SMB encryption on the Sensitive share only., Disable SMBv1 on FileSrv1..
Why this is the answer
To ensure SMB traffic for the "Sensitive" share is encrypted without affecting other shares, you must enable SMB encryption specifically on that share. This setting is granular and applies only to the specified share. To prevent the use of SMBv1 on FileSrv1, you need to disable the SMBv1 protocol at the server level. This action affects all shares on FileSrv1, fulfilling the requirement. Requiring SMB signing via Group Policy would enforce signing, not encryption, and would apply to all domain members, not just the "Sensitive" share. Enabling SMB encryption globally would encrypt all shares on FileSrv1, which contradicts the requirement to only encrypt the "Sensitive" share. Enabling object access auditing tracks access attempts but does not encrypt data or prevent SMBv1.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed