
GIAC Cyber Incident Leader
Domain 1Objective 2
Credential Attacks GCIL Practice Questions (Page 2)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 6–10
- 6
What is a distinguishing characteristic of a password spraying attack?
Select an answer first - 7
An organization uses NTLM authentication for legacy applications. A security team wants to reduce the risk of pass-the-hash attacks without breaking these applications. Which control is most appropriate?
Select an answer first - 8
Which of the following is a common phishing technique designed to steal credentials?
Select an answer first - 9
A company suspects that a keylogger is present on several employee laptops. The security team wants to detect and remove the keylogger while minimizing disruption. Which approach is most effective?
Select an answer first - 10
A company is migrating to a new identity provider and wants to implement a password policy that balances security against user productivity. The security team is concerned about brute-force attacks, password spraying, and credential reuse. Which policy is most effective while minimizing user friction?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.