Courseiva
SMB Security →mediumMultiple Choice

GCIH SMB Security Practice Question

During an incident investigation at a manufacturing firm, you capture SMB traffic on the internal network. You observe a workstation establishing an SMB2 session to a file server, and within the same TCP connection, the client sends a request to access the file share '\fileserver\Accounting' and then immediately sends a request to access the share '\fileserver\HR'. Both Tree Connect requests succeed and use the same SessionId. What does this activity most likely indicate?

⚠ Common exam trap

The trap here is assuming that multiple Tree Connect requests in one session indicate malicious lateral movement or share enumeration, when in fact it is normal for a user with access to multiple shares.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The client is using a single authenticated SMB session to access multiple shares on the same server, which is normal behavior for a user with access to both shares.

In SMB2, a client authenticates once to create a session, then can issue multiple Tree Connect requests to access different shares on the same server within that session. This is efficient and expected when a user has permissions to multiple shares. The activity described is benign and consistent with normal file access patterns, not an attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The client is using a single authenticated SMB session to access multiple shares on the same server, which is normal behavior for a user with access to both shares.

    Why this is correct

    In SMB2, a single session (established via Session Setup) can be used to connect to multiple shares on the same server by issuing separate Tree Connect requests, each with a different share path. This is standard behavior when a user has permissions to multiple shares and is accessing them concurrently, such as during normal file operations.

  • ✗

    The client is exploiting a vulnerability in the SMB server that allows session hijacking across shares.

    Why it's wrong here

    Session hijacking would involve an attacker taking over an existing session, often from a different source IP or with anomalous parameters. The scenario describes a single client establishing a session and accessing two shares normally; there is no evidence of hijacking, and SMB2 does not permit cross-share session hijacking in this manner.

  • ✗

    The client is performing a brute-force attack against multiple shares on the same server.

    Why it's wrong here

    A brute-force attack would manifest as repeated failed authentication attempts, often with different credentials or rapid Session Setup requests, not successful Tree Connect requests to two different shares using the same authenticated session. The scenario explicitly states both Tree Connect requests succeed, indicating valid access, not a password-guessing campaign.

  • ✗

    The client is attempting to escalate privileges by connecting to a share with higher permissions after accessing a lower-privileged share.

    Why it's wrong here

    Privilege escalation via SMB would involve attempting to access shares or files without proper authorization, typically resulting in access denied errors or unusual session setup with different credentials. Here, both Tree Connects succeed, indicating the user already has legitimate access to both shares, so no escalation is occurring.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.