
GIAC Cyber Incident Leader
Domain 1Objective 2
Credential Attacks GCIL Practice Questions (Page 6)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
9concepts
Questions 26–30
- 26
An organization wants to defend against dictionary attacks on its VPN. The VPN uses username/password authentication. Which control is most effective?
Select an answer first - 27
What is the most effective control to mitigate credential phishing?
Select an answer first - 28
A company recently discovered that a large set of username/password pairs from a third-party breach is being used to log into employee accounts on the corporate VPN. The security team wants to reduce the risk of these compromised credentials being used successfully while minimizing disruption to the workforce. Which combination of controls should be implemented first?
Select an answer first - 29
Which of the following is a best practice to defend against credential attacks?
Select an answer first - 30
A company has a mature security awareness program, but users still occasionally fall for phishing emails that steal their credentials. The security team wants to implement a control that reduces the impact of these successful phishes without requiring users to change their behavior. Which control is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.