CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

A security researcher demonstrates that two different input files can be crafted to produce the identical output when processed by a hashing algorithm with a small digest size, allowing an attacker to substitute a malicious file for a legitimate one without detection. This scenario best illustrates which type of vulnerability?

  1. AA birthday attack (hash collision)
  2. BA replay attack
  3. CA downgrade attack
  4. DA cryptographic side-channel attack
Show answer & explanation

Correct answer: A. A birthday attack (hash collision)

A birthday attack exploits the probability that two different inputs produce the same hash output (a collision), which becomes more likely with smaller digest sizes; this can be leveraged to substitute malicious content while preserving the same hash value.

Why the other options are wrong

  • B. A replay attack reuses captured legitimate data/transactions, not crafted colliding files.
  • C. A downgrade attack forces use of a weaker protocol version, not hash collisions.
  • D. A side-channel attack exploits physical implementation leakage (timing, power), not mathematical collisions.

Birthday Attack / Hash Collision

A cryptographic attack that exploits the mathematical probability of two different inputs producing the same hash output, undermining hash integrity guarantees.

  • Named after the birthday paradox in probability
  • Risk increases with smaller hash digest sizes (e.g., MD5, SHA-1)
  • Mitigated by using strong, collision-resistant algorithms like SHA-256

Memory trick: Just like shared birthdays in a room, hash collisions happen sooner than expected.

More Threats, Vulnerabilities, and Mitigations questions