GCIH SMB Security Practice Question
A security analyst is examining SMB traffic captured during an incident. The analyst observes a series of SMB2 Session Setup requests followed by Tree Connect requests to the IPC$ share, then attempts to access the srvsvc named pipe. The source IP is an internal workstation, and the destination is a domain controller. The workstation's user account is a standard domain user. Which of the following activities is the analyst MOST likely observing?
⚠ Common exam trap
A common mix-up: candidates confuse SMB enumeration with SMB relay; enumeration involves direct queries, while relay involves intercepting and forwarding authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker using the workstation to enumerate domain controller shares and services via SMB.
The observed traffic pattern—Session Setup, Tree Connect to IPC$, and srvsvc named pipe access—is characteristic of SMB enumeration. Attackers commonly use this technique to gather information about shares, users, and services on a target. A standard domain user can perform such enumeration if not restricted, making it a likely step in reconnaissance before lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A user running a legitimate administrative script that queries the domain controller for share information.
Why it's wrong here
While administrative scripts may access srvsvc, they typically run with elevated privileges. The scenario specifies a standard domain user, who would not normally have rights to query srvsvc on a domain controller. This makes legitimate administrative activity unlikely.
- ✗
A misconfigured application on the workstation attempting to access a remote file share.
Why it's wrong here
A misconfigured application would typically attempt to access a specific share, not IPC$ or srvsvc. The IPC$ share is used for inter-process communication and enumeration, not normal file access. This option does not match the observed traffic pattern.
- ✓
An attacker using the workstation to enumerate domain controller shares and services via SMB.
Why this is correct
The sequence of Session Setup, Tree Connect to IPC$, and access to srvsvc is classic SMB enumeration. Tools like net view or PowerShell's Get-SmbShare use srvsvc to list shares. A standard user can often perform this enumeration, making it a likely precursor to further attacks.
- ✗
An attacker performing SMB relay to escalate privileges on the domain controller.
Why it's wrong here
SMB relay involves intercepting and relaying authentication attempts, typically from a client to a server. Here, the traffic originates from a workstation to a domain controller, but the sequence of IPC$ and srvsvc is more indicative of enumeration than relay. Relay would involve a third party, not direct access from a workstation.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.