Access Control, Authentication, and Password Security
Free GIAC Security Essentials practice — 6 questions on Access Control, Authentication, and Password Security, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Access Control, Authentication, and Password Security
A security engineer is selecting a password hashing algorithm for a new web application storing millions of user credentials. The application must resist GPU-based cracking attacks while allowing a tunable work factor to increase over time as hardware improves. Which algorithm BEST meets these requirements?
bcrypt is designed specifically for password storage. It uses the Blowfish cipher's key schedule internally, which makes it comparatively expensive to implement efficiently on GPUs, and its cost factor can be increased over time to keep pace with faster hardware, directly meeting both requirements in the scenario.
Question 2 of 6 · Access Control, Authentication, and Password Security
An analyst suspects a golden ticket attack has occurred in an Active Directory environment. Which indicator is the STRONGEST evidence of this specific attack?
A golden ticket is a forged TGT created offline using a stolen krbtgt hash, so the attacker sets arbitrary ticket attributes such as lifetime, group memberships, and encryption type without going through the domain controller's normal AS-REQ validation. A TGT lifetime that violates domain policy (e.g., far exceeding the configured max) is a well-known forensic indicator specific to forged tickets.
Question 3 of 6 · Access Control, Authentication, and Password Security
Which statement accurately describes the Biba integrity model as applied to a mandatory access control system?
The Biba model's Simple Integrity Axiom prevents reading data of lower integrity (no read down), and its *-Integrity Axiom prevents writing to data of higher integrity (no write up). This protects high-integrity data from being contaminated by lower-integrity subjects or data.
Question 4 of 6 · Access Control, Authentication, and Password Security
Which mitigation is MOST effective at preventing pass-the-hash attacks in a Windows Active Directory environment?
Pass-the-hash relies on extracting NTLM hashes cached in LSASS memory and replaying them for authentication without knowing the plaintext password. Credential Guard uses virtualization-based security to isolate LSASS secrets from the OS kernel, preventing tools like Mimikatz from dumping usable hashes even with local admin/SYSTEM access, directly addressing the root cause.
Question 5 of 6 · Access Control, Authentication, and Password Security
An organization implements certificate-based mutual authentication for VPN clients. Which statement about this approach is TRUE?
Mutual TLS/certificate-based authentication is asymmetric: each party holds a private key that must remain secret and never transmitted, while the corresponding public key (embedded in a certificate) is presented and validated by the other party, proving possession of the private key without exposing it.
Question 6 of 6 · Access Control, Authentication, and Password Security
A penetration tester discovers that a legacy application stores password hashes using unsalted SHA-1. Which attack technique is made significantly EASIER by the absence of a salt?
Without a unique salt per password, identical plaintext passwords always produce identical hashes, and attackers can use precomputed rainbow tables of common password-to-hash mappings to instantly reverse many hashes across the entire database at once, rather than needing to attack each one individually.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.