Password and Credential Attacks for GIAC Certified Incident Handler (GCIH)
This page covers the Password and Credential Attacks domain of the GIAC Certified Incident Handler (GCIH) certification. Master Cybersecurity offers 21 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which of the following types of attack can guess a hashed password?- A. Brute force attack
- B. Evasion attack
- C. Denial of Service attack
- D. Teardrop attack
Explanation
The correct answer is: A. Brute force attack.
A brute force attack can guess a hashed password because the hash gives the attacker a way to test candidates offline. Hashing is one-way, so the stored value cannot be reversed, but it is also deterministic: an attacker holding the hash can compute the hash of each candidate password and compare, and once the values match the original password is known. This is why exposure of a hash database is serious even though no plaintext was stored, and why deliberately slow, salted hashing functions exist to make each guess expensive. The other options do not target credentials. An evasion attack manipulates how traffic is presented so that a monitoring device and the destination interpret it differently. A denial of service attack aims at availability. A teardrop attack sends overlapping fragments a vulnerable stack cannot reassemble, which is a specific denial of service technique. None of them recovers a password from a hash.
Question 2
Which of the following statements are true about a keylogger? Each correct answer represents a complete solution. (Choose all that apply.)- A. It records all keystrokes on the victim's computer in a predefined log file.
- B. It can be remotely installed on a computer system.
- C. It is a software tool used to trace all or specific activities of a user on a computer.
- D. It uses hidden code to destroy or scramble data on the hard disk.
Explanation
The correct answers are: A. It records all keystrokes on the victim's computer in a predefined log file., B. It can be remotely installed on a computer system., C. It is a software tool used to trace all or specific activities of a user on a computer..
Three of the statements describe a keylogger correctly. It records keystrokes on the victim's computer into a predefined log file, which is its core function and the reason it captures credentials so effectively, since a password is typed before any encryption is applied to it. It can be installed remotely, typically bundled with other malicious software or delivered through an exploit, so physical access is not required. It is also fairly described as a tool for tracing all or specific activity of a user, since many implementations extend beyond keystrokes to capture window titles, screenshots and visited sites. The false statement is the one describing hidden code that destroys or scrambles data on the hard disk. That is destructive malware, and it is the opposite of what a keylogger is for: a logger's value depends entirely on remaining unnoticed for as long as possible, so damaging the host would defeat its own purpose.
Question 3
You work as a Network Administrator for Tech Perfect Inc. The company has a TCP/IP-based network. An attacker uses software that keeps trying password combinations until the correct password is found. Which type of attack is this?- A. Denial-of-Service
- B. Man-in-the-middle
- C. Brute Force
- D. Vulnerability
Explanation
The correct answer is: C. Brute Force.
Software that keeps trying password combinations until the correct one is found is performing a brute force attack. The defining characteristic is exhaustive search: the tool works through the candidate space systematically rather than relying on any insight about the password, which is why brute force will always succeed given enough time and why the practical defences are account lockout, rate limiting, and password length sufficient to make the search space unmanageable. The other options describe unrelated activity. A denial of service seeks to exhaust a resource so legitimate users cannot reach a service, and it is not concerned with discovering credentials. A man-in-the-middle attack places the attacker between two parties to read or alter traffic in transit, which obtains a credential by interception rather than by guessing. A vulnerability is a weakness in a system rather than a technique, so it does not name an attack at all.
Question 4
Which of the following are types of access control attacks? Each correct answer represents a complete solution. (Choose all that apply.)- A. Spoofing
- B. Brute force attack
- C. Dictionary attack
- D. Mail bombing
Explanation
The correct answers are: A. Spoofing, B. Brute force attack, C. Dictionary attack.
Spoofing, brute force and dictionary attacks are all attacks against access control, because each is an attempt to defeat the mechanism that decides who may use a system. Spoofing does so by presenting a forged identity so the system grants rights belonging to someone else. Brute force works through candidate credentials exhaustively until one is accepted. A dictionary attack does the same with a curated list of likely passwords, trading coverage for speed. All three end with the attacker holding access they were not entitled to. Mail bombing is the exception: it floods a mailbox or mail server with a large volume of messages in order to exhaust storage or make the service unusable. That is an availability attack, and it succeeds without the attacker ever obtaining an identity or a credential, which is why it sits outside this category however disruptive it may be.
Question 5
Which of the following is spy software that records activity on Macintosh systems via snapshots, keystrokes, and Web site logging?- A. Spector
- B. Magic Lantern
- C. eblaster
- D. NetBus
Explanation
The correct answer is: A. Spector.
Spector is monitoring software available for Macintosh systems that records activity by taking periodic screen snapshots, logging keystrokes and recording the web sites visited, which matches the description exactly. Products of this kind occupy an awkward middle ground: they are sold commercially for parental and workplace monitoring, yet the capability is indistinguishable from spyware when installed without the knowledge of the person being watched. The other options are different products on different platforms. Magic Lantern was a keystroke-logging tool associated with law enforcement rather than a commercial Macintosh monitoring product. eBlaster comes from the same commercial family but is characterised by forwarding recorded activity reports by electronic mail, whereas the description here centres on snapshots and local logging. NetBus is a remote access trojan for Windows, giving an attacker interactive control of a machine rather than performing passive activity recording.
Other GIAC Certified Incident Handler (GCIH) domains
- Exploitation and Privilege Escalation (20 questions)
- Incident Response and Cyber Investigation (57 questions)
- Malware, Persistence, and Covering Tracks (105 questions)
- Network Attacks and Denial of Service (86 questions)
- Reconnaissance, Scanning, and Mapping (86 questions)
- Web Application Attacks (29 questions)