20+ practice questions focused on Understanding Passwords — one of the most tested topics on the GIAC Certified Incident Handler exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Understanding Passwords PracticeRefer to the exhibit. An attacker is attempting to guess passwords against a Linux service. Why does this lockout mechanism fail to prevent a distributed brute-force attack?
Explanation: The lockout mechanism is account-based, meaning it only tracks failures for a single target. Distributed attacks use botnets to cycle through thousands of unique IP addresses and target credentials, rotating passwords so that no single account triggers the threshold. Incident responders must implement rate limiting based on IP and behavioral analytics to augment static lockout policies, which are easily bypassed by modern credential stuffing botnets that use distributed infrastructure.
Which THREE of the following are primary components of modern password policy best practices?
Explanation: Modern password policies focus on usability and security over arbitrary complexity requirements. Research indicates that forcing frequent password changes leads to weaker, predictable patterns. Instead, organizations should mandate minimum lengths, check against lists of known compromised passwords, and utilize MFA. These approaches provide significantly better protection against modern threats by increasing the cost of compromise while reducing the likelihood of users choosing weak, easily guessed passwords or writing them down on sticky notes.
Refer to the exhibit. Which configuration change would be the most effective for improving the security of this authentication system?
Explanation: The current configuration is dangerously weak due to MD5, zero salt, and low iterations. Moving to a modern, adaptive, and slow hashing function like Argon2id is the single most impactful change. Argon2id incorporates memory-hard and time-hard parameters that are specifically resistant to GPU-based cracking. Increasing the iteration count alone is insufficient if the underlying algorithm is inherently broken, as MD5/SHA algorithms are simply too fast to be secure against modern hardware attacks.
An incident handler is investigating a breach where the attacker successfully brute-forced a password file. The hashes were generated using bcrypt with a high work factor. What does this suggest about the attacker's capabilities?
Explanation: Bcrypt is a intentionally slow, CPU-intensive, and memory-hard function. If an attacker successfully cracked a significant portion of the database using bcrypt, they likely possess massive computational power (such as a large-scale botnet or high-end GPU/FPGA clusters) or the passwords chosen by users were extremely weak/common. This situation forces the responder to assume a high-resource adversary and likely requires a full forced password reset, as the security controls were likely overwhelmed by brute force.
An incident responder is reviewing authentication logs from a Windows Server 2022 domain controller. The logs show a series of failed logon attempts for the same user account, occurring every few seconds from a single source IP. The account lockout policy is set to lock after 5 failed attempts within 15 minutes. The responder notices that after the fifth failed attempt, the account is locked, but the attacker continues to generate failed logon events for that account. Which of the following best explains why the attacker continues to generate failed logon events after the account is locked?
Explanation: After an account is locked, authentication attempts still reach the domain controller and are evaluated. The system logs a failed logon event for each attempt because the credentials are checked and then rejected due to the lockout. Automated brute-force tools often do not stop after lockout, so they continue to generate events, which can be useful for detection but also indicates the attack persists.
+15 more Understanding Passwords questions available
Practice all Understanding Passwords questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Understanding Passwords. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Understanding Passwords questions on the GCIH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Understanding Passwords is tested as part of the GIAC Certified Incident Handler blueprint. Practicing with targeted Understanding Passwords questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCIH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Understanding Passwords is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Understanding Passwords practice session with instant scoring and detailed explanations.
Start Understanding Passwords Practice →