
GIAC Certified Incident Handler
Domain 4Objective 2
Understanding Passwords GCIH Practice Questions (Page 6)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
7concepts
Questions 26–30
- 26
A security analyst notices a large number of failed login attempts against the VPN gateway, all using usernames from a list of common names and passwords from a standard wordlist. The attempts are spread over several hours. Which defensive measure would be most effective to stop this attack?
Select an answer first - 27
What is a recommended best practice for creating a strong password?
Select an answer first - 28
How does multi-factor authentication (MFA) enhance security beyond a password alone?
Select an answer first - 29
What is the primary security risk of storing passwords in plaintext?
Select an answer first - 30
Which attack involves an attacker trying a list of common passwords or words against a user account?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.