
GIAC Certified Incident Handler
Domain 4Objective 1
Attacking Passwords GCIH Practice Questions (Page 7)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
8concepts
Questions 31–35
- 31
Which scenario best describes an offline password attack?
Select an answer first - 32
A company has experienced a credential stuffing attack. Which post-incident measure would be most effective in preventing future credential stuffing attacks?
Select an answer first - 33
An incident responder has two tasks: crack a set of captured NTLM hashes and test the organization's web application login for weak passwords. The responder wants to avoid detection and account lockouts. Which approach BEST balances effectiveness and stealth?
Select an answer first - 34
A company wants to reduce the risk of credential stuffing attacks against its web application. Which control is most effective at directly mitigating this specific attack?
Select an answer first - 35
In a pass-the-hash attack, what does the attacker use to authenticate to a remote system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.