A city GPO legacy setting disables SMB signing domain-wide. What conceptual link should the tester make in the report?
Select an answer to reveal the explanation.
Short Explanation
SMB signing is the handshake that says 'this session was not quietly redirected.' Switch it off domain-wide and you weaken a key defense against relay-shaped mischief. Call the GPO out as a hardening miss.
Full Explanation
SMB signing helps ensure session integrity and is commonly discussed alongside mitigations for credential-relay scenarios. Domain-wide disablement via legacy GPO is therefore a meaningful hardening gap. It does not by itself enforce Kerberos-only auth, nor is antivirus currency a substitute for signing policy. Conceptual linkage to relay resistance is appropriate in CPTS-style findings.