
GIAC Certified Incident Handler
Domain 4Objective 2
Understanding Passwords GCIH Practice Questions (Page 8)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
7concepts
Questions 36–39
- 36
An organization wants to encourage employees to use unique, complex passwords for each service without requiring them to memorize dozens of passwords. Which solution best meets this need?
Select an answer first - 37
A small business wants to improve password security without deploying complex infrastructure. Employees currently reuse the same password across multiple sites. Which solution is the most practical first step?
Select an answer first - 38
Which password cracking technique involves trying every possible combination of characters until the correct password is found?
Select an answer first - 39
A company is deploying a password manager. The security team is concerned about the master password being the single point of failure. They want to implement a solution that reduces the risk of master password compromise while maintaining usability. Which approach is most effective?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.