Courseiva

GSEC · topic practice

Access Control and Password Management practice questions

This GSEC domain covers identity, authentication, and authorization controls: discretionary, mandatory, and role-based models, plus attribute-based decisions. It tests password storage and hygiene, multifactor authentication, and least privilege. Expect scenario questions asking you to select the correct access control model, hashing algorithm, or password practice for a stated business or threat condition.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Access Control and Password Management

What the exam tests

What to know about Access Control and Password Management

Be able to match an access control model to a scenario, pick a memory-hard salted hashing algorithm for stored passwords, and apply least privilege and MFA. The single most important thing: separate authentication from authorization and never store passwords with fast, unsalted hashes.

Selecting DAC, MAC, RBAC, or ABAC for a described access decision requirement

Choosing a memory-hard password hashing algorithm such as Argon2 over fast hashes

Applying least privilege through role assignment, sudo, and file permissions

Recognizing MFA, lockout, and unique-credential practices that blunt credential stuffing

Watch out for

Common Access Control and Password Management exam traps

  • ▸Confusing authentication (proving identity) with authorization (granting access), then picking an answer that fixes the wrong layer
  • ▸Choosing fast hashes like MD5 or SHA-256 for password storage instead of salted, memory-hard algorithms
  • ▸Treating least privilege as one-time setup rather than continuous review and removal of excess rights

Practice set

Access Control and Password Management questions

20 questions · select your answer, then reveal the explanation

An organization requires that users authenticate via a smart card and a PIN to access secure network resources. Which access control model is being enforced?

Refer to the exhibit. An administrator applies this JSON policy to an S3 bucket. What is the intended effect of this access control policy?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::data-bucket/*",
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "false"
        }
      }
    }
  ]
}

Which TWO of the following are considered 'something you are' authentication factors?

A system administrator implements a policy where users can only access the server room during their scheduled shifts. Which type of access control is this?

Refer to the exhibit. Based on the error log, why was the request denied?

Exhibit

Error: AccessDenied
User: arn:aws:iam::1234567890:user/jdoe
Request: s3:PutObject
Resource: arn:aws:s3:::finance-records/q4.pdf
Context: User is assigned to group 'Finance_Read_Only'

A security engineer is configuring a Linux server that hosts a shared financial application. The company's access control policy mandates that authentication and authorization decisions be made by a central server, and that users be granted access based on their role in the finance department. The engineer installs and configures the SSSD daemon to integrate with the corporate LDAP directory. Which access control model is being implemented?

A security administrator is configuring a Linux server to enforce a password policy that locks an account for 30 minutes after five failed login attempts within a 10-minute window. The administrator wants to avoid locking out the root account to prevent accidental denial of service. Which file should be edited to apply these settings?

A user reports that they are unable to log into their workstation after returning from vacation. The help desk verifies that the user's account is not locked out and the password has not expired. Which of the following is the most likely cause?

Which password management practice best minimizes the impact of a credential stuffing attack?

Which of the following describes the 'Principle of Least Privilege' in an access control context?

What is the primary purpose of Salt in password hashing?

A security administrator is reviewing the password policy for a high-security environment. The policy requires the use of a hardware token that generates a one-time password (OTP) based on a secret key and the current time. The administrator notices that some tokens are failing authentication because the server and tokens are not time-synchronized. Which of the following should the administrator implement to ensure the OTPs are validated correctly?

A security team is configuring password policies for a Windows Active Directory domain. They need to enforce a setting that prevents users from reusing any of their last 24 passwords. Which password policy setting should they configure?

Question 14hardmultiple choice
Read the full VPN explanation →

A security administrator is reviewing authentication logs and notices that an attacker successfully authenticated to a VPN using a valid username and password, but the attacker did not possess the user's hardware token. The VPN is configured to require both a password and a one-time code from a hardware token. Which attack technique most likely allowed the attacker to bypass the hardware token requirement?

A security team is implementing a new access control system for a research lab. They need to ensure that access decisions are based on the user's role and the sensitivity of the resource, and that users are only granted the minimum permissions necessary to perform their job. Which two access control principles should they apply? (Choose two.)

A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)

A security analyst is reviewing authentication logs and notices that an attacker attempted to log in using a list of previously breached username and password combinations. The attack failed because the organization had implemented a control that requires users to provide a second factor in addition to their password. Which type of attack was mitigated?

Question 18mediummultiple choice
Read the full VPN explanation →

An organization is deploying a new VPN solution and wants to ensure that authentication credentials are not transmitted in cleartext over the internet. The security team decides to use a protocol that encapsulates authentication within a TLS tunnel. Which protocol should they implement?

A security administrator is configuring a Linux server and needs to enforce that all user passwords are hashed with a strong, salted algorithm. Which file should the administrator edit to set the default password hashing algorithm for new passwords?

A security engineer is designing a password hashing scheme for a new application. The scheme must be resistant to GPU-accelerated cracking and allow for tuning of CPU and memory costs. Which hashing algorithm should the engineer choose?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Access Control and Password Management sessions

Start a Access Control and Password Management only practice session

Every question in these sessions is drawn from the Access Control and Password Management domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Access Control and Password Management?
Be able to match an access control model to a scenario, pick a memory-hard salted hashing algorithm for stored passwords, and apply least privilege and MFA. The single most important thing: separate authentication from authorization and never store passwords with fast, unsalted hashes.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Access Control and Password Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Access Control and Password Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.