Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 4Objective 2

Understanding Passwords GCIH Practice Questions (Page 5)

Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
7concepts

Questions 21–25

  1. 21application · medium

    A company's password policy currently requires passwords to be changed every 90 days and to be at least 10 characters long. The security team wants to reduce the risk of credential stuffing attacks. Which change would be most effective?

    Select an answer first
  2. 22foundation · easy

    What is the primary advantage of a rainbow table attack over a traditional brute-force attack?

    Select an answer first
  3. 23application · medium

    A company's security team discovers that a phishing campaign successfully harvested the Active Directory passwords of 40 employees. The team is relieved to find that no unauthorized access occurred. Which control already in place is most likely responsible for preventing the attackers from using the stolen passwords?

    Select an answer first
  4. 24foundation · easy

    Which password policy element is most effective at increasing resistance to brute-force attacks?

    Select an answer first
  5. 25foundation · easy

    Which characteristic is commonly associated with a strong password?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.