A vulnerability scan returns a finding on legacy file servers: 'SMBv1 enabled.' The servers still host read-only shares for an application that cannot be updated. Which interpretation best describes the risk indicated by this finding?
Select an answer to reveal the explanation.
Short Explanation
Think of SMBv1 like leaving an old back door unlocked because a legacy app still needs it. A scanner flagging it isn't saying malware is inside; it's saying you've widened the target and need to disable that old protocol. Your job is to close the exposure, not chase a breach that the scan didn't prove.
Full Explanation
SMBv1 is an obsolete file-sharing protocol retained for compatibility. A scanner finding that it is enabled is a configuration exposure, not proof of compromise: it tells you a legacy feature is reachable and likely supports known weaknesses, so the attack surface is elevated until the feature is disabled, the servers are isolated, or compensating controls are applied. A finding of active compromise would require corroborating telemetry such as suspicious process creation, authentication anomalies, or file integrity changes, not merely the presence of a protocol. A claim that the scanner misreported the result is weak because SMBv1 can still be enabled on older or improperly hardened systems, even when newer platforms default to disabling it. A claim that the finding is a missing patch is also incorrect: SMBv1 is a server/client feature or protocol setting, so remediation focuses on disabling the component and validating configuration, not applying a single update. Exam caveat: treat deprecated protocol findings as configuration and exposure questions unless the item provides exploit or malware evidence. Operational check: inspect SMBv1 state on the file servers using SMB configuration or registry settings, disable SMBv1 where dependencies allow, then rerun the scan to confirm the finding closes.