Courseiva

GSEC Access Control and Password Management Practice Question

A security analyst is reviewing authentication logs and notices that an attacker attempted to log in using a list of previously breached username and password combinations. The attack failed because the organization had implemented a control that requires users to provide a second factor in addition to their password. Which type of attack was mitigated?

⚠ Common exam trap

Many candidates confuse credential stuffing with password spraying, as both involve multiple login attempts, but credential stuffing uniquely uses breached credentials from other services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Credential stuffing

Credential stuffing specifically uses breached username and password pairs to gain unauthorized access. The presence of a second authentication factor prevents the attacker from succeeding even with valid credentials. Other attacks like password spraying, brute force, or rainbow tables do not rely on breached credential lists in the same way. Therefore, the mitigated attack is credential stuffing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rainbow table attack

    Why it's wrong here

    A rainbow table attack uses precomputed hash tables to crack password hashes. It targets stored password databases, not live login attempts. The scenario involves an attacker attempting to log in with breached credentials, not cracking hashes. Rainbow tables are mitigated by salting hashes, not by second factors. Thus, this attack type does not match the described situation.

  • ✓

    Credential stuffing

    Why this is correct

    Credential stuffing uses lists of username and password pairs obtained from data breaches on other sites. Attackers assume users reuse credentials across services. The scenario explicitly mentions a list of previously breached combinations, which is the hallmark of credential stuffing. Requiring a second factor (like a one-time code) prevents unauthorized access even if the password is correct, effectively mitigating this attack.

  • ✗

    Brute force

    Why it's wrong here

    Brute force attacks systematically try all possible combinations or use large dictionaries against a single account. The scenario describes using breached credentials from other sites, not exhaustive guessing. While brute force can be mitigated by account lockout or second factors, the specific attack vector here is credential stuffing. Brute force would not rely on previously breached username/password pairs.

  • ✗

    Password spraying

    Why it's wrong here

    Password spraying involves trying a few common passwords against many accounts to avoid lockouts. In this scenario, the attacker used a list of breached credentials, which is characteristic of credential stuffing, not spraying. Spraying typically uses a small set of passwords like 'Password123' across many usernames. The presence of a second factor would also mitigate spraying, but the specific attack described is credential stuffing.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.