
GIAC Cyber Incident Leader
Domain 1Objective 2
Credential Attacks GCIL Practice Questions (Page 1)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 1–5
- 1
A security team is evaluating controls to reduce the risk of credential stuffing and password spraying against their customer-facing web application. The application is used by a large number of customers, and the team wants to avoid locking out legitimate users. Which approach is most effective?
Select an answer first - 2
A user reports that their bank account was accessed from a foreign IP address. An investigation shows that the user's computer had a keylogger that captured the bank's login credentials. Which defense would have been most effective in preventing the attacker from using the captured credentials?
Select an answer first - 3
A company is planning a defense-in-depth strategy against credential attacks. They have limited budget and must choose between two controls: implementing MFA for all users or deploying a SIEM to monitor authentication logs. Which approach is most effective?
Select an answer first - 4
A security analyst notices a high volume of failed login attempts against the company's web application. The attempts use a list of common passwords (e.g., 'Password123', 'Summer2024') but each attempt uses a different username. The analyst wants to block this activity without locking out legitimate users. Which action is most appropriate?
Select an answer first - 5
A company's security team is investigating a breach where an attacker used a keylogger to capture a user's password and then accessed the user's corporate email. The team wants to implement a control that would prevent this from happening again, but the company has a policy that prohibits the use of MFA for email access due to cost. Which control is most effective under this constraint?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.