Courseiva
Attacking Passwords →mediumMultiple Choice

GCIH Attacking Passwords Practice Question

Which of the following best describes the risk of using 'credential stuffing' against a web application, and how does it differ from a standard dictionary attack?

⚠ Common exam trap

Candidates often confuse credential stuffing with dictionary attacks, failing to realize that stuffing relies on the reuse of valid leaked credentials rather than brute-forcing new passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stuffing tests leaked credentials; dictionary attacks guess passwords

Credential stuffing uses previously leaked username/password pairs from one service to gain unauthorized access to another. It differs from a dictionary attack because it utilizes valid, known credentials rather than guessing passwords. This is highly effective because users often reuse passwords across multiple sites, making it a critical threat to organizations that do not enforce multifactor authentication (MFA) or monitor for logins from unusual locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dictionary attacks use compromised lists; stuffing uses random passwords

    Why it's wrong here

    Dictionary attacks use lists of common words or previously identified passwords to guess credentials. Credential stuffing specifically uses lists of *valid, stolen* credentials from other breaches. The distinction lies in the origin and verified nature of the password list used by the attacker.

  • ✓

    Stuffing tests leaked credentials; dictionary attacks guess passwords

    Why this is correct

    Credential stuffing exploits the human tendency to reuse passwords by automating logins with verified pairs from other breaches. Dictionary attacks are purely probabilistic attempts to guess a password for a single target, making them fundamentally different in execution and success rates.

  • ✗

    Dictionary attacks are faster than credential stuffing

    Why it's wrong here

    Credential stuffing is often faster in practice because it leverages high-probability credentials. Dictionary attacks may take significant time to successfully guess a single password. The speed comparison is inaccurate, as both are limited by the target's authentication rate-limiting protections.

  • ✗

    Stuffing targets the database; dictionary attacks target the login

    Why it's wrong here

    Credential stuffing targets the login interface directly, not the database. It simulates a user attempting to log in. It is not an injection attack on the database itself, but rather an exploitation of the authentication service via automated front-end requests.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.