GSEC Access Control and Password Management Practice Question
Which password management practice best minimizes the impact of a credential stuffing attack?
⚠ Common exam trap
Candidates often select 'frequent password changes' as the answer, failing to realize that frequent changes do not prevent credential stuffing if the same password is used everywhere.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforcing unique passwords per service
Credential stuffing relies on users reusing the same passwords across multiple services. By enforcing unique, complex passwords for every single account, users ensure that a compromise at one service does not lead to a cascade of compromises elsewhere. This is the single most effective defense against automated attacks that attempt to use leaked database dumps to gain unauthorized access to other unrelated accounts held by the same user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mandating password changes every 30 days
Why it's wrong here
Frequent forced password rotations often lead users to choose weaker, predictable passwords or simply iterate on previous ones. This behavior defeats the purpose of rotation and provides little protection against credential stuffing, as attackers usually test the most recently stolen credentials immediately regardless of how often the password is reset.
- ✗
Requiring a minimum password length of 8 characters
Why it's wrong here
While length is important for resisting brute-force guessing attacks, it does not stop credential stuffing. Since the attacker already has valid credentials, they do not need to guess the password; they simply need to use it. A short password is just as effective for an attacker as a long one.
- ✓
Enforcing unique passwords per service
Why this is correct
Unique passwords ensure that even if one account's credentials are breached in a data leak, the attacker cannot use those same credentials to access other platforms. This containment strategy isolates the impact of a breach and prevents the automated success typically associated with large-scale credential stuffing campaigns against modern web services.
- ✗
Disabling account lockout after failed attempts
Why it's wrong here
Disabling account lockout policies is generally dangerous because it allows attackers to perform unlimited brute-force or dictionary attacks. While it might prevent a DoS situation, it does nothing to stop a credential stuffing attack, which uses valid, known credentials rather than trial-and-error guessing methods that trigger typical lockout mechanisms.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.