GCIH SMB Security Practice Question
A healthcare organization's incident response team is investigating unusual SMB activity on a Windows file server. NetFlow data shows a single internal workstation opened SMB connections to more than 200 distinct hosts on TCP 445 within five minutes, and each connection lasted under two seconds. The workstation's user reports no unusual behavior. Which of the following is the most likely explanation for this traffic pattern?
⚠ Common exam trap
The trap here is dismissing the pattern as benign network discovery or backup activity because the user reports nothing unusual, when the breadth and speed of short-lived SMB connections indicate automated malicious scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The workstation is infected with malware performing SMB worm-style lateral movement or network discovery.
A single workstation opening TCP 445 connections to over 200 distinct hosts in five minutes, with each session lasting under two seconds, matches automated SMB scanning or worm-style lateral movement. Legitimate backup or load-balancing traffic would be documented, targeted, and longer-lived. The silent nature of the activity and the user's unawareness reinforce malware as the likely cause, so the host should be isolated and examined.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file server is load-balancing SMB sessions across the network, causing the workstation to reconnect frequently.
Why it's wrong here
SMB session load balancing would involve the workstation connecting to multiple servers that host the same share, but it would not generate 200 distinct destinations from a single client in minutes. Load balancing also tends to produce longer, stable sessions rather than sub-two-second connections. The traffic direction here is the workstation initiating to many hosts, which is the opposite of a server-side balancing behavior.
- ✗
The workstation is experiencing a DNS misconfiguration causing it to resolve many hostnames to the same server.
Why it's wrong here
A DNS misconfiguration would cause repeated connections to a small number of addresses, not connections to 200 distinct hosts. NetFlow shows unique destination IPs, so name resolution errors would not produce this spread. Additionally, DNS issues typically cause failed connections and user-visible errors, not a silent fan-out of SMB sessions. The breadth and speed point to deliberate scanning rather than a name resolution fault.
- ✓
The workstation is infected with malware performing SMB worm-style lateral movement or network discovery.
Why this is correct
Hundreds of short-lived TCP 445 connections to many distinct hosts in a brief window is a hallmark of automated SMB scanning or worm propagation. Malware such as ransomware worms enumerate reachable SMB hosts, attempt connections, and move on quickly when they fail or succeed. The user's lack of awareness supports a silent, automated process. This pattern warrants immediate isolation and forensic triage of the workstation.
- ✗
A legitimate backup application is enumerating shares across the environment.
Why it's wrong here
Backup applications typically connect to a defined set of servers and maintain longer sessions to read data, rather than opening hundreds of sub-two-second connections to random hosts. While some discovery tools exist, a backup job would usually be scheduled and documented, and the user would not be surprised. The rapid, broad, short-lived pattern is more consistent with automated scanning or worm-like propagation than with a normal backup enumeration workflow.
Visual reference
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.