
GIAC Certified Incident Handler
Domain 4Objective 2
Understanding Passwords GCIH Practice Questions (Page 7)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
7concepts
Questions 31–35
- 31
A web application developer is choosing a password storage method. The developer is considering using bcrypt with a cost factor of 12. A security reviewer asks why bcrypt is preferred over SHA-256 for password storage. What is the primary reason?
Select an answer first - 32
A company is evaluating password managers for its employees. The security team is comparing a cloud-based password manager and a locally-hosted password manager. What is a key security advantage of a locally-hosted password manager?
Select an answer first - 33
A company has been hit by a phishing campaign that harvested employee passwords. Even after resetting passwords, management wants to reduce the impact of future credential theft. Which additional control would be most effective?
Select an answer first - 34
A company is implementing MFA for all employees. The security team is concerned about phishing-resistant authentication but also needs to support employees who travel internationally and may not have reliable cellular service. Which MFA method is the best choice?
Select an answer first - 35
How does a password manager typically protect the stored password database?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.