Courseiva

GCIH Endpoint Attack and Pivoting Practice Question

An incident responder is examining a compromised Windows 10 workstation that an attacker used to pivot into the internal network. The responder runs `netstat -ano` and sees an established connection from the workstation to an internal server on TCP port 445, but no user has mapped a drive or accessed a share. Which of the following Windows artifacts would BEST reveal the remote service or process that initiated this SMB connection?

⚠ Common exam trap

The trap here is assuming that Windows Security event logs alone will identify the process behind a network connection, when in fact process-level network attribution requires Sysmon or similar telemetry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sysmon Event ID 3 (network connection detected)

Sysmon Event ID 3 captures network connection events with the initiating process image, source and destination IPs, and ports. On the compromised workstation, this event directly links the SMB connection to a specific executable or service, which is exactly what the responder needs. Other artifacts either reside on the remote server, lack process context, or do not record network activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows Security event ID 4624 with logon type 3

    Why it's wrong here

    Event ID 4624 with logon type 3 indicates a network logon, but it does not record the process or service that initiated the connection. It shows the account and source IP, but not the local executable responsible. In this scenario, the attacker may have used a service or scheduled task to make the connection, and 4624 alone would not reveal that process, making it insufficient to answer the question.

  • ✗

    Security event ID 5140 (network share object was accessed)

    Why it's wrong here

    Event ID 5140 is logged on the file server when a network share is accessed, not on the workstation that initiated the connection. It would show the share name and the account used, but it would not identify the client-side process or service that opened the SMB session. The scenario asks for the artifact on the compromised workstation that reveals the initiating process, so this event is on the wrong host and lacks process context.

  • ✓

    Sysmon Event ID 3 (network connection detected)

    Why this is correct

    Sysmon Event ID 3 logs network connections with the source and destination IP addresses, ports, and the Image (process) that initiated the connection. On the compromised workstation, this event would directly tie the SMB connection to a specific executable or service, such as a malicious binary or a living-off-the-land tool. This is the most direct artifact to identify the remote service or process that created the connection.

  • ✗

    Prefetch file for the executable that made the connection

    Why it's wrong here

    Prefetch files show that an executable ran on the system, along with timestamps and loaded modules, but they do not record network connections or remote endpoints. While useful for execution evidence, Prefetch cannot associate a specific process with the SMB connection observed in netstat. It would not identify the remote service or process that initiated the connection, so it is not the best artifact here.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.