Courseiva
Understanding Passwords →mediumMultiple Choice

GCIH Understanding Passwords Practice Question

Which of the following scenarios best demonstrates why multi-factor authentication (MFA) is superior to password-only authentication?

⚠ Common exam trap

Test-takers frequently choose options related to encryption or phishing resistance generally, forgetting that the core superiority of MFA lies specifically in defeating stolen password credentials through orthogonal verification factors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It prevents unauthorized access despite password theft

MFA introduces a secondary requirement that is independent of the password. Even if an attacker obtains the password through phishing, credential stuffing, or a database breach, they cannot gain access without the second factor (like a physical security key or a time-based token). This breaks the single point of failure that exists with password-only systems, rendering stolen credentials useless for unauthorized account access, which is the ultimate goal of the adversary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It makes passwords faster to type for users

    Why it's wrong here

    MFA typically makes the login process slower, not faster. It adds a step for the user, which is a known usability trade-off. The justification for MFA is security, not efficiency; users often view it as an inconvenience, but it is necessary to protect accounts against credential theft.

  • ✗

    It eliminates the need for complex passwords

    Why it's wrong here

    Even with MFA, strong, unique passwords are still necessary. If an attacker gains access to both the password and the MFA token (via session hijacking or social engineering), they can bypass both. MFA is an additional layer of security, not a replacement for strong password hygiene and policy.

  • ✓

    It prevents unauthorized access despite password theft

    Why this is correct

    MFA creates a requirement for a second, separate piece of evidence. If an attacker steals a password, they still lack the second factor (such as a TOTP app or a hardware token). This makes the stolen password insufficient for the attacker to successfully complete the authentication process.

  • ✗

    It ensures that the password never expires

    Why it's wrong here

    MFA does not change the rules regarding password expiration. While it reduces the pressure to rotate passwords frequently, the two are independent concepts. An organization can still require password changes even when MFA is implemented, as they serve different purposes in the overall security strategy.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.