A water utility still allows legacy LM or NTLMv1 preference in parts of the environment. What risk awareness should the tester communicate?
Select an answer to reveal the explanation.
Short Explanation
Old auth dialects are like cheap locks that skilled thieves already know how to pick. If LM or NTLMv1 is still in the mix, credential theft themes get easier. Push for modern authentication settings.
Full Explanation
Legacy LAN Manager and NTLMv1 negotiation weaken authentication material relative to modern NTLMv2/Kerberos-focused configurations. That weakness historically aids credential-capture and related techniques, so it is a meaningful hardening gap. Such preferences do not disable Kerberos forest-wide, nor do they imply mandatory SMB signing. Conceptual awareness of legacy auth risk is appropriate for CPTS-style reporting.