GSEC Access Control and Password Management Practice Question
A security administrator is reviewing authentication logs and notices that an attacker successfully authenticated to a VPN using a valid username and password, but the attacker did not possess the user's hardware token. The VPN is configured to require both a password and a one-time code from a hardware token. Which attack technique most likely allowed the attacker to bypass the hardware token requirement?
⚠ Common exam trap
The trap here is assuming that a hardware token makes authentication immune to interception, forgetting that real-time relay attacks can capture and reuse one-time codes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Man-in-the-middle attack
A man-in-the-middle attack allows an attacker to intercept and relay authentication credentials, including one-time codes, in real time. If the attacker can position themselves between the user and the VPN, they can capture both the password and the token code as they are transmitted. The attacker then uses these to authenticate before the code expires, effectively bypassing the need to physically possess the hardware token. Other attacks like pass-the-hash, credential stuffing, or brute-force do not provide the one-time code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Credential stuffing
Why it's wrong here
Credential stuffing uses leaked username/password pairs from other breaches to attempt logins. It relies on password reuse and does not involve bypassing a second factor. In this scenario, the attacker already has a valid username and password, but still needs the hardware token. Credential stuffing would not provide the one-time code, so it cannot explain the successful authentication without the token.
- ✗
Pass-the-hash
Why it's wrong here
Pass-the-hash involves capturing an NTLM hash and using it to authenticate without knowing the plaintext password. It is typically used for lateral movement within Windows environments. However, it does not bypass a hardware token requirement because the token generates a separate one-time code that is not derived from the password hash. The scenario requires both password and token, so pass-the-hash alone would not succeed.
- ✓
Man-in-the-middle attack
Why this is correct
A man-in-the-middle attack can intercept the authentication session and relay the one-time code in real time. If the attacker positions themselves between the user and the VPN, they can capture the password and the token code as the user submits them, then use them to authenticate before the code expires. This allows bypassing the hardware token requirement without possessing the physical token.
- ✗
Brute-force attack
Why it's wrong here
A brute-force attack attempts to guess the password or token code by trying many combinations. One-time codes are typically short-lived and rate-limited, making brute-force impractical. Even if the password is guessed, the attacker would still need the current token code, which changes frequently. Brute-force does not explain how the attacker obtained a valid one-time code without the token.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.