Courseiva
SMB Security →easyMultiple Choice

GCIH SMB Security Practice Question

An incident handler is reviewing SMB traffic and notices a large number of SMB2 CREATE requests for files with extensions like .docx, .xlsx, and .pdf, followed by SMB2 WRITE requests that overwrite the same files with encrypted content. The traffic originates from a single workstation and targets a file server. Which type of attack is most likely occurring?

⚠ Common exam trap

The trap here is assuming that any SMB file modification is benign; however, overwriting files with encrypted content is a strong indicator of ransomware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ransomware encrypting files on the file server via SMB.

The correct answer is ransomware encrypting files via SMB. The sequence of opening document files and overwriting them with encrypted data is a hallmark of ransomware. The other options do not match the observed traffic: exfiltration would read files, brute-force would show failed logons, and worm propagation would target multiple hosts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ransomware encrypting files on the file server via SMB.

    Why this is correct

    The pattern of opening document files and overwriting them with encrypted content is characteristic of ransomware. SMB is commonly used by ransomware to encrypt files on network shares. The high volume of CREATE and WRITE requests from one workstation to a file server indicates malicious encryption activity.

  • ✗

    SMB worm propagation, where the attacker is scanning for vulnerable hosts.

    Why it's wrong here

    Worm propagation would involve scanning and exploitation attempts, such as SMB2 NEGOTIATE requests to multiple hosts, not file encryption on a single server. The described traffic is focused on file operations on one server, which is typical of ransomware, not a worm scanning the network.

  • ✗

    Data exfiltration through SMB, where files are being copied to an external location.

    Why it's wrong here

    Data exfiltration would involve reading files (SMB2 READ) and transferring them out, not overwriting them with encrypted content. The scenario describes WRITE requests that overwrite files, which is destructive and consistent with encryption, not exfiltration. Exfiltration typically does not alter the original files.

  • ✗

    SMB brute-force attack, where the attacker is attempting to guess passwords.

    Why it's wrong here

    A brute-force attack would generate numerous failed authentication attempts (logon failures), not successful CREATE and WRITE operations. The scenario shows successful file operations, indicating the attacker already has valid credentials or access. Brute-force would not result in file modifications.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.