
GIAC Cyber Incident Leader
Domain 1Objective 2
Credential Attacks GCIL Practice Questions (Page 5)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 21–25
- 21
An incident responder finds that an attacker used a stolen Kerberos ticket to access a file server. The ticket was issued for a service account that has access to sensitive data. The organization wants to limit the impact of similar attacks in the future. Which control is most effective?
Select an answer first - 22
A small business uses a legacy application that only supports password authentication. The IT admin wants to reduce the risk of brute-force attacks on the application's login page. Which control would be most effective given the application's limitation?
Select an answer first - 23
Which password attack method involves trying every possible combination of characters until the correct password is found?
Select an answer first - 24
During a red team exercise, the team captured a user's password hash from a compromised workstation and then used it to access a file share. The file share is configured to accept NTLM authentication. Which change would most directly prevent this type of attack?
Select an answer first - 25
What is the main risk of credential reuse?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.