CompTIA Server+ (SK0-005)TroubleshootingMedium
A server administrator attempts to access a shared folder on a Windows file server from a Linux client using SMB/CIFS, but receives an 'Access Denied' error. Other Windows clients can access the share without issues. The Linux client is able to ping the server by IP and resolve its hostname. What is the MOST likely cause of this issue?
- ASMBv1 is disabled on the Windows server and the Linux client is attempting to use it
- BIncorrect DNS settings on the Linux client
- CNTFS permissions are not correctly configured for the Linux user's credentials
- DFirewall blocking SMB ports on the Linux client
Show answer & explanationAnswer & explanation
Correct answer: A. SMBv1 is disabled on the Windows server and the Linux client is attempting to use it
Modern Windows servers (and clients) often have SMBv1 disabled by default due to security vulnerabilities. If a Linux client's SMB implementation defaults to or is configured to only use SMBv1, it would fail to connect, resulting in an 'Access Denied' or similar connection error, even if network connectivity and user credentials are correct.
Why the other options are wrong
- B. DNS is working as the client can resolve the hostname; this would not cause an 'Access Denied' for a share.
- C. While NTFS permissions are crucial, the problem states 'other Windows clients can access the share without issues', implying the NTFS permissions on the share are likely correct for the user's credentials. The issue is more fundamental to the connection protocol.
- D. A firewall on the Linux client blocking outbound SMB would prevent any connection, not necessarily an 'Access Denied' after initial connection attempt. Also, the problem states 'Access Denied', implying a successful connection handshake but authorization failure.
SMBv1 Deprecation
SMBv1 (Server Message Block version 1) is an outdated and insecure network file sharing protocol that is often disabled by default on modern operating systems.
- Superseded by SMBv2 and SMBv3.
- Known for security vulnerabilities (e.g., WannaCry).
- Disabling it can break compatibility with older clients/devices.
Memory trick: Old protocols block new connections.