GCIH Endpoint Attack and Pivoting Practice Question
Which of the following describes the 'SMB Relay' attack during lateral movement?
⚠ Common exam trap
Candidates frequently mistake SMB Relay for a credential-cracking attack. They assume the attacker is trying to decrypt the intercepted hash rather than immediately using it to authenticate to another machine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intercepting authentication and relaying it to another machine.
SMB Relay works by intercepting a client's authentication request (SMB) and forwarding it to another target machine. If the client has sufficient privileges, the attacker gains access to the target without ever needing the user's password. This attack is particularly dangerous in environments without SMB signing enabled, as it allows for easy lateral movement through man-in-the-middle positioning within the local network segment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypting files on the network share.
Why it's wrong here
Encrypting files is the objective of ransomware, not a pivoting technique. SMB Relay is about intercepting and relaying authentication requests to impersonate a user. It does not involve mass encryption of data, which would be an extremely loud action that would trigger immediate detection by security teams.
- ✓
Intercepting authentication and relaying it to another machine.
Why this is correct
This accurately describes the mechanism of an SMB Relay attack. By positioning themselves as a man-in-the-middle, the attacker captures the authentication handshake and forwards it to a destination server. This allows the attacker to authenticate as the victim, effectively pivoting to a new host without cracking passwords.
- ✗
Sending flood packets to crash the SMB service.
Why it's wrong here
Sending flood packets is a Denial of Service (DoS) technique, not an attack for lateral movement or pivoting. The goal of an attacker during lateral movement is to maintain access and control, not to destroy service availability, which would only draw unwanted attention to their activities.
- ✗
Replacing the SMB.exe binary with a malicious version.
Why it's wrong here
SMB is a protocol implemented within the kernel and system services; there is no single binary named 'SMB.exe'. Replacing system-level protocol handlers is extremely difficult due to file integrity protections. SMB Relay is a network-layer attack, not a file replacement attack, making this option technically incorrect.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.