
GIAC Security Essentials
Domain 1Objective 1
Access Control & Password Management GSEC Practice Questions (Page 5)
Part of the Foundations of Security domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 21–25
- 21
A security auditor discovers that a legacy application stores user passwords using unsalted MD5 hashes. The auditor also notes that many users have the same password. What is the most significant risk?
Select an answer first - 22
A security auditor finds that the application stores passwords in plaintext. Which risk is the most direct consequence?
Select an answer first - 23
A security engineer is evaluating password storage options for a new application. The application must support high login throughput, but the security team requires strong protection against offline attacks. Which approach best balances these concerns?
Select an answer first - 24
An organization wants to implement MFA for remote access. Which combination represents two different authentication factors?
Select an answer first - 25
An employee uses a password manager to store credentials for multiple corporate applications. The employee's laptop is stolen, but the password manager requires a master password and biometric authentication. What is the primary security benefit of this setup?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.