GSEC · domain
Access Control and Password Management
This GSEC domain covers identity, authentication, and authorization controls: discretionary, mandatory, and role-based models, plus attribute-based decisions. It tests password storage and hygiene, multifactor authentication, and least privilege. Expect scenario questions asking you to select the correct access control model, hashing algorithm, or password practice for a stated business or threat condition.
Focused practice
Practice Access Control and Password Management questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Access Control and Password Management
Be able to match an access control model to a scenario, pick a memory-hard salted hashing algorithm for stored passwords, and apply least privilege and MFA. The single most important thing: separate authentication from authorization and never store passwords with fast, unsalted hashes.
Selecting DAC, MAC, RBAC, or ABAC for a described access decision requirement
Choosing a memory-hard password hashing algorithm such as Argon2 over fast hashes
Applying least privilege through role assignment, sudo, and file permissions
Recognizing MFA, lockout, and unique-credential practices that blunt credential stuffing
Watch out for
Common Access Control and Password Management exam traps
- ▸Confusing authentication (proving identity) with authorization (granting access), then picking an answer that fixes the wrong layer
- ▸Choosing fast hashes like MD5 or SHA-256 for password storage instead of salted, memory-hard algorithms
- ▸Treating least privilege as one-time setup rather than continuous review and removal of excess rights
Question index
All Access Control and Password Management questions (13)
Click any question to see the full explanation, or start a practice session above.
A security team is configuring password policies for a Windows Active Directory domain. They need to enforce a setting that prevents users from reusing any of their last 24 passwords. Which password policy setting should they configure?
Medium2Which of the following describes the 'Principle of Least Privilege' in an access control context?
Easy3What is the primary purpose of Salt in password hashing?
Easy4A security administrator is hardening authentication on a set of Linux servers that will be accessed by third-party contractors. Management requires that contractors authenticate with a one-time code delivered by a hardware token, while local administrators continue to use their existing passwords, and that both methods can be used on the same SSH service without changing the client software. Which approach best meets these requirements?
Hard5A security team is implementing a new access control system for a research lab. They need to ensure that access decisions are based on the user's role and the sensitivity of the resource, and that users are only granted the minimum permissions necessary to perform their job. Which two access control principles should they apply? (Choose two.)
Medium6A security analyst is reviewing authentication logs and notices that an attacker attempted to log in using a list of previously breached username and password combinations. The attack failed because the organization had implemented a control that requires users to provide a second factor in addition to their password. Which type of attack was mitigated?
Easy7A security administrator is reviewing authentication logs and notices that an attacker successfully authenticated to a VPN using a valid username and password, but the attacker did not possess the user's hardware token. The VPN is configured to require both a password and a one-time code from a hardware token. Which attack technique most likely allowed the attacker to bypass the hardware token requirement?
Hard8An organization is deploying a new VPN solution and wants to ensure that authentication credentials are not transmitted in cleartext over the internet. The security team decides to use a protocol that encapsulates authentication within a TLS tunnel. Which protocol should they implement?
Medium9Which password management practice best minimizes the impact of a credential stuffing attack?
Medium10A security administrator is configuring a Linux server and needs to enforce that all user passwords are hashed with a strong, salted algorithm. Which file should the administrator edit to set the default password hashing algorithm for new passwords?
Medium11A security administrator is reviewing the password policy for a high-security environment. The policy requires the use of a hardware token that generates a one-time password (OTP) based on a secret key and the current time. The administrator notices that some tokens are failing authentication because the server and tokens are not time-synchronized. Which of the following should the administrator implement to ensure the OTPs are validated correctly?
Hard12A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)
Hard13A security engineer is designing a password hashing scheme for a new application. The scheme must be resistant to GPU-accelerated cracking and allow for tuning of CPU and memory costs. Which hashing algorithm should the engineer choose?
HardOther domains
All GSEC exam domains
Frequently asked questions
- What does the Access Control and Password Management domain cover on the GSEC exam?
- Be able to match an access control model to a scenario, pick a memory-hard salted hashing algorithm for stored passwords, and apply least privilege and MFA. The single most important thing: separate authentication from authorization and never store passwords with fast, unsalted hashes.
- How many questions are in this domain?
- This page lists all 13 Access Control and Password Management questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Access Control and Password Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.