GCIH Attacking Passwords Practice Question
Which of the following best describes the risk of using 'credential stuffing' against a web application, and how does it differ from a standard dictionary attack?
⚠ Common exam trap
Candidates often confuse credential stuffing with dictionary attacks, failing to realize that stuffing relies on the reuse of valid leaked credentials rather than brute-forcing new passwords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stuffing tests leaked credentials; dictionary attacks guess passwords
Credential stuffing uses previously leaked username/password pairs from one service to gain unauthorized access to another. It differs from a dictionary attack because it utilizes valid, known credentials rather than guessing passwords. This is highly effective because users often reuse passwords across multiple sites, making it a critical threat to organizations that do not enforce multifactor authentication (MFA) or monitor for logins from unusual locations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dictionary attacks use compromised lists; stuffing uses random passwords
Why it's wrong here
Dictionary attacks use lists of common words or previously identified passwords to guess credentials. Credential stuffing specifically uses lists of *valid, stolen* credentials from other breaches. The distinction lies in the origin and verified nature of the password list used by the attacker.
- ✓
Stuffing tests leaked credentials; dictionary attacks guess passwords
Why this is correct
Credential stuffing exploits the human tendency to reuse passwords by automating logins with verified pairs from other breaches. Dictionary attacks are purely probabilistic attempts to guess a password for a single target, making them fundamentally different in execution and success rates.
- ✗
Dictionary attacks are faster than credential stuffing
Why it's wrong here
Credential stuffing is often faster in practice because it leverages high-probability credentials. Dictionary attacks may take significant time to successfully guess a single password. The speed comparison is inaccurate, as both are limited by the target's authentication rate-limiting protections.
- ✗
Stuffing targets the database; dictionary attacks target the login
Why it's wrong here
Credential stuffing targets the login interface directly, not the database. It simulates a user attempting to log in. It is not an injection attack on the database itself, but rather an exploitation of the authentication service via automated front-end requests.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.