
GIAC Certified Incident Handler
Domain 4Objective 2
Understanding Passwords GCIH Practice Questions (Page 2)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
7concepts
Questions 6–10
- 6
A developer is designing a new web application and wants to store user passwords securely. The application will run in a cloud environment and must comply with internal security standards. Which approach should the developer choose?
Select an answer first - 7
A company is updating its password policy. The security team wants to balance security with usability. Which policy element is most effective at mitigating credential-stuffing attacks, where attackers use username/password pairs leaked from other sites?
Select an answer first - 8
Which of the following is an example of a possession factor in multi-factor authentication?
Select an answer first - 9
In the context of authentication, what is the primary role of a password?
Select an answer first - 10
A company has been the target of a credential-stuffing attack. The security team has implemented MFA for all users, but the attack continues. Analysis shows that the attacker is using valid credentials that have been obtained from a previous breach. Which additional control is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.