Be able to match an access control model to a scenario, pick a memory-hard salted hashing algorithm for stored passwords, and apply least privilege and MFA. The single most important thing: separate authentication from authorization and never store passwords with fast, unsalted hashes.
Start practicing
Access Control and Password Management — choose a session length
Free · No account required
Domain overview
This GSEC domain covers identity, authentication, and authorization controls: discretionary, mandatory, and role-based models, plus attribute-based decisions. It tests password storage and hygiene, multifactor authentication, and least privilege. Expect scenario questions asking you to select the correct access control model, hashing algorithm, or password practice for a stated business or threat condition.
Exam objectives
Selecting DAC, MAC, RBAC, or ABAC for a described access decision requirement
Choosing a memory-hard password hashing algorithm such as Argon2 over fast hashes
Applying least privilege through role assignment, sudo, and file permissions
Recognizing MFA, lockout, and unique-credential practices that blunt credential stuffing
Confusing authentication (proving identity) with authorization (granting access), then picking an answer that fixes the wrong layer
Choosing fast hashes like MD5 or SHA-256 for password storage instead of salted, memory-hard algorithms
Treating least privilege as one-time setup rather than continuous review and removal of excess rights
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which password management practice best minimizes the impact of a credential stuffing attack?
2Which of the following describes the 'Principle of Least Privilege' in an access control context?
3What is the primary purpose of Salt in password hashing?
4A security administrator is reviewing the password policy for a high-security environment. The policy requires the use of a hardware token that generates a one-time password (OTP) based on a secret key and the current time. The administrator notices that some tokens are failing authentication because the server and tokens are not time-synchronized. Which of the following should the administrator implement to ensure the OTPs are validated correctly?
5A security team is configuring password policies for a Windows Active Directory domain. They need to enforce a setting that prevents users from reusing any of their last 24 passwords. Which password policy setting should they configure?
6A security administrator is reviewing authentication logs and notices that an attacker successfully authenticated to a VPN using a valid username and password, but the attacker did not possess the user's hardware token. The VPN is configured to require both a password and a one-time code from a hardware token. Which attack technique most likely allowed the attacker to bypass the hardware token requirement?
7A security team is implementing a new access control system for a research lab. They need to ensure that access decisions are based on the user's role and the sensitivity of the resource, and that users are only granted the minimum permissions necessary to perform their job. Which two access control principles should they apply? (Choose two.)
8A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)
9A security analyst is reviewing authentication logs and notices that an attacker attempted to log in using a list of previously breached username and password combinations. The attack failed because the organization had implemented a control that requires users to provide a second factor in addition to their password. Which type of attack was mitigated?
10An organization is deploying a new VPN solution and wants to ensure that authentication credentials are not transmitted in cleartext over the internet. The security team decides to use a protocol that encapsulates authentication within a TLS tunnel. Which protocol should they implement?
11A security administrator is configuring a Linux server and needs to enforce that all user passwords are hashed with a strong, salted algorithm. Which file should the administrator edit to set the default password hashing algorithm for new passwords?
12A security engineer is designing a password hashing scheme for a new application. The scheme must be resistant to GPU-accelerated cracking and allow for tuning of CPU and memory costs. Which hashing algorithm should the engineer choose?
13A security administrator is hardening authentication on a set of Linux servers that will be accessed by third-party contractors. Management requires that contractors authenticate with a one-time code delivered by a hardware token, while local administrators continue to use their existing passwords, and that both methods can be used on the same SSH service without changing the client software. Which approach best meets these requirements?
Be able to match an access control model to a scenario, pick a memory-hard salted hashing algorithm for stored passwords, and apply least privilege and MFA. The single most important thing: separate authentication from authorization and never store passwords with fast, unsalted hashes.
The Courseiva GSEC question bank contains 13 questions in the Access Control and Password Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Access Control and Password Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included