Courseiva

GCIH · topic practice

Understanding Passwords practice questions

This GCIH domain covers how passwords are stored, attacked, and defended during incident response. You must recognize compromise indicators, understand hashing weaknesses, and explain why GPU and rainbow-table attacks succeed against unsalted or fast hashes. Questions are scenario-based, often asking you to select two correct answers from a breach or password-database review scenario.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Understanding Passwords

What the exam tests

What to know about Understanding Passwords

Be able to identify signs of a password-database compromise and explain how salting, slow hashing algorithms, and unique per-user salts resist offline cracking. The single most important point: fast unsalted hashes fall quickly to GPU and rainbow-table attacks, while salted adaptive hashes do not.

Identifying breach indicators such as unusual authentication logs, dumped hash files, or mass password resets

Recognizing password hashing best practices including salting, key stretching, and slow adaptive algorithms

Explaining why GPUs outperform CPUs for parallel hash cracking due to many cores and high memory bandwidth

Evaluating hash resistance based on salt uniqueness, algorithm work factor, and hash length

Watch out for

Common Understanding Passwords exam traps

  • ▸Assuming encryption and hashing are interchangeable; password databases store one-way hashes, not reversible ciphertext
  • ▸Believing a single strong password stops offline cracking; weak or reused passwords still fall after a hash dump
  • ▸Confusing salting with encryption; salts prevent precomputed rainbow tables but do not hide the hash itself

Practice set

Understanding Passwords questions

20 questions · select your answer, then reveal the explanation

Refer to the exhibit. An attacker is attempting to guess passwords against a Linux service. Why does this lockout mechanism fail to prevent a distributed brute-force attack?

Exhibit

LOG_ENTRY: user 'admin' failed login 5 times. Status: 0x4002. Policy: Lockout after 3 attempts. Action: Account locked.

Which THREE of the following are primary components of modern password policy best practices?

Refer to the exhibit. Which configuration change would be the most effective for improving the security of this authentication system?

Exhibit

CONFIG: auth_method = 'plain'; password_hash = 'MD5'; iteration_count = 1000; salt_length = 0;

An incident handler is investigating a breach where the attacker successfully brute-forced a password file. The hashes were generated using bcrypt with a high work factor. What does this suggest about the attacker's capabilities?

An incident responder is reviewing authentication logs from a Windows Server 2022 domain controller. The logs show a series of failed logon attempts for the same user account, occurring every few seconds from a single source IP. The account lockout policy is set to lock after 5 failed attempts within 15 minutes. The responder notices that after the fifth failed attempt, the account is locked, but the attacker continues to generate failed logon events for that account. Which of the following best explains why the attacker continues to generate failed logon events after the account is locked?

An incident responder is reviewing an authentication server's logs and notices that a single user account is being targeted with thousands of login attempts per minute from a distributed set of IP addresses. The server enforces account lockout after 5 failed attempts, but the attacker never triggers the lockout. Which of the following password attack techniques is most likely being used?

A security analyst is reviewing authentication logs from a web application that uses bcrypt for password storage. The application's configuration specifies a cost factor of 10. The analyst notices that during peak hours, the authentication process is slow, causing user complaints. Which of the following changes would BEST balance security and performance while maintaining resistance to offline cracking?

A security analyst is examining a Windows environment where an attacker has obtained a copy of the SAM database. The analyst notices that the LM hash for a user account is present but the NT hash is not. Which of the following best explains why the LM hash is present?

An incident responder is analyzing a Windows environment where an attacker has obtained a copy of the SAM database. The responder observes that the LM hash values are present for several user accounts. Which two of the following statements accurately describe the security implications of LM hashes in this scenario? (Choose two.)

An incident responder notices that a legacy web application stores user credentials using MD5 hashing without salt. Which vulnerability is the primary risk during a credential database compromise?

Which TWO of the following are considered best practices for password hashing to mitigate offline cracking?

What is the primary function of a salt in password storage?

Which of the following describes a 'credential stuffing' attack?

Why are GPUs highly effective at cracking password hashes compared to traditional CPUs?

Why does the use of pepper provide additional security for password hashes, and where should it ideally be stored?

Which of the following is an advantage of using a Key Derivation Function (KDF) like Argon2 over a simple hash like SHA-256?

Which TWO of the following are common indicators that a password database has been compromised?

Which of the following scenarios best demonstrates why multi-factor authentication (MFA) is superior to password-only authentication?

During an incident response engagement at a financial services firm, you discover that the attacker obtained a copy of the /etc/shadow file from a compromised Linux server. The file contains hashes generated with the SHA-512 crypt scheme ($6$). Which of the following is the MOST accurate assessment of the attacker's ability to recover plaintext passwords from these hashes?

A security analyst is examining a Linux system that uses shadow password files. The analyst notices that the password hashes are stored in /etc/shadow and are prefixed with $6$. Which of the following best describes the hashing algorithm used for these passwords?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Understanding Passwords sessions

Start a Understanding Passwords only practice session

Every question in these sessions is drawn from the Understanding Passwords domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Understanding Passwords?
Be able to identify signs of a password-database compromise and explain how salting, slow hashing algorithms, and unique per-user salts resist offline cracking. The single most important point: fast unsalted hashes fall quickly to GPU and rainbow-table attacks, while salted adaptive hashes do not.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Understanding Passwords questions in a focused session?
Yes — the session launcher on this page draws every question from the Understanding Passwords domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.