Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 6Objective 1

Password Attacks on Cloud Environments GCPN Practice Questions (Page 10)

Part of the Credential Attacks and Evasion domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
8concepts

Questions 46–48

  1. 46application · medium

    A penetration tester is conducting a password spraying test against a company's Azure AD. The tester has a list of 500 usernames and wants to test 10 common passwords. The tenant has a lockout threshold of 10 failed attempts per 15 minutes per user. What is the maximum number of passwords the tester can test per user in a 15-minute window without locking the account?

    Select an answer first
  2. 47foundation · easy

    Which action is essential when executing a password spraying attack to avoid locking out accounts?

    Select an answer first
  3. 48expert · hard

    A security architect is designing defenses against password attacks for a cloud environment. The organization wants to minimize user friction while protecting against password spraying and brute force. Which combination of controls best meets this requirement?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCPN

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.