CompTIA Security+ (SY0-701)General Security ConceptsHard
A developer stores user passwords by first appending a unique random value to each password before hashing it, and storing that random value alongside the hash. What is the primary security benefit of this technique?
- AIt reduces the storage size required for the password database
- BIt ensures the hash output is reversible with the correct key
- CIt encrypts the password so it can be decrypted later if needed
- DIt prevents attackers from using precomputed rainbow tables against the hashes
Show answer & explanationAnswer & explanation
Correct answer: D. It prevents attackers from using precomputed rainbow tables against the hashes
Salting adds a unique random value to each password before hashing, which defeats precomputed rainbow table attacks because attackers would need a separate table for every unique salt, making the attack impractical.
Why the other options are wrong
- A. Salting slightly increases storage requirements since the salt must be stored too.
- B. Hashes remain irreversible even with the salt; there is no key to reverse them.
- C. Hashing is one-way and is never intended to be decrypted, unlike encryption.
Salting
Adding a unique random value to a password before hashing to prevent precomputed hash (rainbow table) attacks and ensure identical passwords produce different hashes.
- Salt is stored alongside the hash, not secret
- Makes each hash unique even for identical passwords
- Often combined with key-stretching algorithms like bcrypt or PBKDF2
Memory trick: Salt spoils the rainbow (table)