Courseiva
SMB Security →hardMultiple Choice

GCIH SMB Security Practice Question

An incident responder is analyzing a memory dump from a compromised Windows workstation. The responder finds evidence of a tool that creates a named pipe and waits for a connection from a domain controller. The tool then relays authentication attempts to another server. Which of the following SMB-based attacks is the responder MOST likely investigating?

⚠ Common exam trap

Many exam-takers confuse hash capture tools like Responder with relay tools like ntlmrelayx; relay involves forwarding authentication, not just capturing it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NTLM relay attack using a tool like ntlmrelayx.

The described tool creates a named pipe and waits for a domain controller connection, then relays authentication attempts to another server. This is characteristic of an NTLM relay attack, often executed with tools like ntlmrelayx from the Impacket suite. Responder captures hashes, Mimikatz performs pass-the-hash, and downgrade attacks manipulate version negotiation, none of which match the relay behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SMB downgrade attack using a custom script.

    Why it's wrong here

    SMB downgrade attacks manipulate version negotiation to force a weaker protocol, but they do not involve creating named pipes or relaying authentication. The described tool's behavior is focused on relaying, not downgrading. This option does not match the evidence.

  • ✗

    Pass-the-hash attack using Mimikatz.

    Why it's wrong here

    Pass-the-hash involves using captured NTLM hashes to authenticate directly, without relaying. Mimikatz can perform pass-the-hash but does not create a named pipe to wait for a domain controller connection. The described behavior is indicative of relay, not direct hash usage.

  • ✗

    SMB relay attack using the Responder tool.

    Why it's wrong here

    Responder is primarily used for poisoning LLMNR, NBT-NS, and mDNS to capture hashes, not for relaying SMB authentication from a domain controller. While it can capture SMB hashes, the described tool creates a named pipe and waits for a domain controller connection, which is more specific to relay attacks using tools like Impacket's ntlmrelayx.

  • ✓

    NTLM relay attack using a tool like ntlmrelayx.

    Why this is correct

    ntlmrelayx creates a named pipe and listens for incoming SMB connections from a target (e.g., domain controller) and relays the authentication to another server. This matches the description of waiting for a domain controller connection and relaying attempts. It is a classic NTLM relay technique.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.