Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 5Objective 2

SMB Security GCIH Practice Questions (Page 7)

Part of the Network and Infrastructure Security domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
7concepts

Questions 31–35

  1. 31application · medium

    A security analyst is reviewing network traffic and sees a large number of SMB2 CREATE requests with malformed headers sent to a Windows server. The server is running an unpatched version of Windows 10. Which vulnerability is the attacker most likely attempting to exploit?

    Select an answer first
  2. 32application · medium

    A company is planning to upgrade its file servers to support the latest SMB features. The security team wants to ensure that the servers support encryption and secure dialect negotiation. Which SMB version should they target?

    Select an answer first
  3. 33application · medium

    A Windows administrator is troubleshooting a performance issue on a file server. The server is running SMB1 because of a legacy application. The administrator wants to improve performance and security. Which action is the best first step?

    Select an answer first
  4. 34application · medium

    A SOC analyst is reviewing a packet capture and sees an SMB2 NEGOTIATE request with a dialect list that includes SMB 2.0.2, 2.1, 3.0, and 3.1.1. The server responds with SMB 3.1.1. What does this indicate about the client and server?

    Select an answer first
  5. 35application · medium

    A security analyst is investigating a series of failed SMB logon attempts from a single IP address. The attempts use usernames that match the company's employee directory and a small set of common passwords. The analyst suspects a password-spraying attack. Which additional evidence would most strongly confirm this hypothesis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.