Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cyber Incident Leader

Domain 1Objective 2

Credential Attacks GCIL Practice Questions (Page 1)

Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
9concepts

Questions 1–5

  1. 1expert · hard

    A security team is evaluating controls to reduce the risk of credential stuffing and password spraying against their customer-facing web application. The application is used by a large number of customers, and the team wants to avoid locking out legitimate users. Which approach is most effective?

    Select an answer first
  2. 2application · medium

    A user reports that their bank account was accessed from a foreign IP address. An investigation shows that the user's computer had a keylogger that captured the bank's login credentials. Which defense would have been most effective in preventing the attacker from using the captured credentials?

    Select an answer first
  3. 3expert · hard

    A company is planning a defense-in-depth strategy against credential attacks. They have limited budget and must choose between two controls: implementing MFA for all users or deploying a SIEM to monitor authentication logs. Which approach is most effective?

    Select an answer first
  4. 4application · medium

    A security analyst notices a high volume of failed login attempts against the company's web application. The attempts use a list of common passwords (e.g., 'Password123', 'Summer2024') but each attempt uses a different username. The analyst wants to block this activity without locking out legitimate users. Which action is most appropriate?

    Select an answer first
  5. 5expert · hard

    A company's security team is investigating a breach where an attacker used a keylogger to capture a user's password and then accessed the user's corporate email. The team wants to implement a control that would prevent this from happening again, but the company has a policy that prohibits the use of MFA for email access due to cost. Which control is most effective under this constraint?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.