Courseiva

GSEC Access Control and Password Management Practice Question

Which password management practice best minimizes the impact of a credential stuffing attack?

⚠ Common exam trap

Candidates often select 'frequent password changes' as the answer, failing to realize that frequent changes do not prevent credential stuffing if the same password is used everywhere.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforcing unique passwords per service

Credential stuffing relies on users reusing the same passwords across multiple services. By enforcing unique, complex passwords for every single account, users ensure that a compromise at one service does not lead to a cascade of compromises elsewhere. This is the single most effective defense against automated attacks that attempt to use leaked database dumps to gain unauthorized access to other unrelated accounts held by the same user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mandating password changes every 30 days

    Why it's wrong here

    Frequent forced password rotations often lead users to choose weaker, predictable passwords or simply iterate on previous ones. This behavior defeats the purpose of rotation and provides little protection against credential stuffing, as attackers usually test the most recently stolen credentials immediately regardless of how often the password is reset.

  • ✗

    Requiring a minimum password length of 8 characters

    Why it's wrong here

    While length is important for resisting brute-force guessing attacks, it does not stop credential stuffing. Since the attacker already has valid credentials, they do not need to guess the password; they simply need to use it. A short password is just as effective for an attacker as a long one.

  • ✓

    Enforcing unique passwords per service

    Why this is correct

    Unique passwords ensure that even if one account's credentials are breached in a data leak, the attacker cannot use those same credentials to access other platforms. This containment strategy isolates the impact of a breach and prevents the automated success typically associated with large-scale credential stuffing campaigns against modern web services.

  • ✗

    Disabling account lockout after failed attempts

    Why it's wrong here

    Disabling account lockout policies is generally dangerous because it allows attackers to perform unlimited brute-force or dictionary attacks. While it might prevent a DoS situation, it does nothing to stop a credential stuffing attack, which uses valid, known credentials rather than trial-and-error guessing methods that trigger typical lockout mechanisms.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.