ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringEasy

A developer is implementing a new web application and is concerned about protecting user authentication credentials. Which of the following cryptographic methods provides a one-way transformation of a password, making it computationally infeasible to reverse engineer the original password, while still allowing verification of its correctness?

  1. ADigital Signatures (e.g., DSA)
  2. BAsymmetric Encryption (e.g., RSA)
  3. CSymmetric Encryption (e.g., AES)
  4. DHashing (e.g., SHA-256)
Show answer & explanation

Correct answer: D. Hashing (e.g., SHA-256)

Hashing functions provide a one-way transformation of data. They produce a fixed-size output (hash value) that is unique to the input, making it infeasible to reverse the process to find the original input. This is ideal for securely storing passwords.

Why the other options are wrong

  • A. Digital signatures provide authenticity and integrity, not one-way password storage.
  • B. Asymmetric encryption is reversible and used for confidentiality and key exchange, not one-way storage.
  • C. Symmetric encryption is reversible and used for confidentiality, not one-way storage.

Hashing

A cryptographic process that transforms input data into a fixed-size string of characters, known as a hash value or message digest.

  • One-way function; computationally infeasible to reverse.
  • Used for integrity checks and password storage.
  • Collision resistance is a crucial property.

Memory trick: Hashes Hide Secrets, Signatures Show Trust, Asymmetric keys Share, Symmetric keys Shield.

More Security Architecture and Engineering questions