GCIH SMB Security Practice Question
An incident responder is analyzing a packet capture and observes a Windows workstation sending an SMB2 NEGOTIATE request listing only the SMB 2.0.2 dialect, followed by a SESSION_SETUP request containing an NTLMSSP Type 3 message. The server responds with STATUS_SUCCESS. The workstation normally communicates with this file server using SMB 3.1.1. What is the most likely explanation for this behavior?
⚠ Common exam trap
The trap here is assuming that any SMB dialect mismatch is a configuration error, when a sudden downgrade combined with NTLMSSP authentication can indicate an active man-in-the-middle attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker performed an SMB downgrade attack by intercepting the negotiation and stripping higher dialect offers.
The correct answer is the scenario where an attacker intercepts SMB negotiation and strips higher dialect offers, forcing the client to use SMB 2.0.2 and NTLMSSP authentication. This is a classic SMB downgrade attack aimed at capturing or relaying credentials. The other options describe misconfigurations or benign fallbacks that do not match the sudden change from SMB 3.1.1 with Kerberos to SMB 2.0.2 with NTLMSSP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The workstation's SMB client is misconfigured to use only SMB 2.0.2 due to a missing registry key.
Why it's wrong here
A misconfiguration would typically cause consistent behavior, but the scenario states the workstation normally uses SMB 3.1.1. The sudden change to 2.0.2 and NTLMSSP suggests external manipulation, not a static configuration issue. Additionally, a registry misconfiguration would not explain the NTLMSSP Type 3 message if Kerberos was previously used successfully.
- ✓
An attacker performed an SMB downgrade attack by intercepting the negotiation and stripping higher dialect offers.
Why this is correct
The workstation normally uses SMB 3.1.1, but the capture shows only SMB 2.0.2 offered and NTLMSSP authentication instead of Kerberos, indicating a man-in-the-middle stripped higher dialects and forced weaker authentication. This aligns with an SMB downgrade attack, where the attacker manipulates negotiation to weaken security and capture or relay credentials.
- ✗
The file server is configured to only accept SMB 2.0.2 connections, forcing the client to downgrade.
Why it's wrong here
If the server only supported SMB 2.0.2, the client would consistently negotiate that dialect. However, the scenario implies the server normally supports SMB 3.1.1, and the sudden appearance of NTLMSSP instead of Kerberos suggests an active interception, not a static server limitation. A server-side restriction would not typically alter the authentication mechanism from Kerberos to NTLM.
- ✗
The capture shows normal fallback behavior because the client and server could not agree on SMB 3.1.1 encryption.
Why it's wrong here
SMB 3.1.1 negotiation failure would not automatically force NTLMSSP authentication; the client would still attempt Kerberos if available. Moreover, fallback due to encryption mismatch would typically be logged and might not result in a successful session with NTLMSSP. The presence of only SMB 2.0.2 and NTLMSSP strongly indicates malicious downgrade rather than benign fallback.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.