Courseiva

GCIH · domain

Understanding Passwords

This GCIH domain covers how passwords are stored, attacked, and defended during incident response. You must recognize compromise indicators, understand hashing weaknesses, and explain why GPU and rainbow-table attacks succeed against unsalted or fast hashes. Questions are scenario-based, often asking you to select two correct answers from a breach or password-database review scenario.

18 questions5 easy11 medium2 hard

Focused practice

Practice Understanding Passwords questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Understanding Passwords

Be able to identify signs of a password-database compromise and explain how salting, slow hashing algorithms, and unique per-user salts resist offline cracking. The single most important point: fast unsalted hashes fall quickly to GPU and rainbow-table attacks, while salted adaptive hashes do not.

Identifying breach indicators such as unusual authentication logs, dumped hash files, or mass password resets

Recognizing password hashing best practices including salting, key stretching, and slow adaptive algorithms

Explaining why GPUs outperform CPUs for parallel hash cracking due to many cores and high memory bandwidth

Evaluating hash resistance based on salt uniqueness, algorithm work factor, and hash length

Watch out for

Common Understanding Passwords exam traps

  • ▸Assuming encryption and hashing are interchangeable; password databases store one-way hashes, not reversible ciphertext
  • ▸Believing a single strong password stops offline cracking; weak or reused passwords still fall after a hash dump
  • ▸Confusing salting with encryption; salts prevent precomputed rainbow tables but do not hide the hash itself

Question index

All Understanding Passwords questions (18)

Click any question to see the full explanation, or start a practice session above.

1

An incident handler is investigating a breach where an attacker gained access to a system that uses a password manager. The password manager stores all user passwords in an encrypted vault protected by a single master password. The attacker was able to extract the encrypted vault and is now attempting to crack the master password offline. Which of the following characteristics of the password manager's key derivation function would most significantly increase the attacker's difficulty?

Hard
2

During an incident response engagement at a financial services firm, you discover that the attacker obtained a copy of the /etc/shadow file from a compromised Linux server. The file contains hashes generated with the SHA-512 crypt scheme ($6$). Which of the following is the MOST accurate assessment of the attacker's ability to recover plaintext passwords from these hashes?

Medium
3

What is the primary function of a salt in password storage?

Easy
4

An incident handler is investigating a compromised web application that stores user passwords using a custom hashing scheme. The application concatenates a user-specific salt with the password and then applies the SHA-256 hash function 10,000 times. The handler notices that the salt is only 4 bytes long and is generated using a predictable random number generator. Which of the following is the most significant weakness in this password storage scheme?

Hard
5

A GCIH incident handler is investigating a Windows 10 workstation compromised by an attacker who briefly gained local administrator access. The attacker ran a utility that extracted credential material while the machine was running, then left. The handler finds no suspicious files in the System32 directory, and the SAM and SYSTEM hives appear unmodified. However, the handler notices that the LSASS process was accessed by a process that is no longer running. Which of the following best describes what the attacker most likely obtained?

Medium
6

A security administrator is configuring a new web application and wants to implement a password hashing scheme that includes a pepper. Where should the pepper be stored to provide the intended security benefit?

Easy
7

Why does the use of pepper provide additional security for password hashes, and where should it ideally be stored?

Medium
8

An incident handler is analyzing a compromised Windows workstation and discovers that the attacker extracted password hashes from the SAM database. The handler wants to determine which types of attacks the attacker could perform using these hashes. (Choose two.)

Medium
9

Which TWO of the following are common indicators that a password database has been compromised?

Medium
10

Why are GPUs highly effective at cracking password hashes compared to traditional CPUs?

Medium
11

Which of the following describes a 'credential stuffing' attack?

Medium
12

Which TWO of the following are considered best practices for password hashing to mitigate offline cracking?

Medium
13

An incident handler is reviewing password storage mechanisms after a breach. The attacker exfiltrated a file containing password hashes. Which of the following TWO characteristics would make the hashes more resistant to offline cracking? (Choose two.)

Medium
14

An incident responder notices that a legacy web application stores user credentials using MD5 hashing without salt. Which vulnerability is the primary risk during a credential database compromise?

Medium
15

Which of the following is an advantage of using a Key Derivation Function (KDF) like Argon2 over a simple hash like SHA-256?

Easy
16

A security analyst is examining a Linux system that uses shadow password files. The analyst notices that the password hashes are stored in /etc/shadow and are prefixed with $6$. Which of the following best describes the hashing algorithm used for these passwords?

Easy
17

Which of the following scenarios best demonstrates why multi-factor authentication (MFA) is superior to password-only authentication?

Medium
18

A junior incident handler is reviewing password storage practices for a legacy application. The application stores passwords as unsalted MD5 hashes. Which of the following best describes the primary risk introduced by the lack of salting?

Easy

Frequently asked questions

What does the Understanding Passwords domain cover on the GCIH exam?
Be able to identify signs of a password-database compromise and explain how salting, slow hashing algorithms, and unique per-user salts resist offline cracking. The single most important point: fast unsalted hashes fall quickly to GPU and rainbow-table attacks, while salted adaptive hashes do not.
How many questions are in this domain?
This page lists all 18 Understanding Passwords questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Understanding Passwords questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcih GIAC-GCIH understanding passwords Practice Questions