Courseiva
easyMultiple Choice

CAS-004 Practice Question: A developer needs to securely store user…

A developer needs to securely store user passwords in a database. Which hashing technique is recommended for password storage?

⚠ Common exam trap

CompTIA CASP+ often tests the misconception that adding a salt to a fast hash like SHA-256 makes it suitable for passwords, but the trap is that without a built-in work factor, the hash remains too fast for attackers to brute-force efficiently.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

bcrypt with a per-user salt

Bcrypt is recommended for password storage because it incorporates a per-user salt to prevent rainbow table attacks and uses a configurable cost factor to slow down brute-force attempts, making it resistant to GPU-based cracking. Unlike general-purpose hashes like SHA-256, bcrypt is designed specifically for password hashing with built-in salting and adaptive work factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SHA-256 with a random salt

    Why it's wrong here

    SHA-256 is a fast general-purpose digest, so GPUs compute billions of guesses per second against stolen hashes; password storage needs a deliberately slow, memory-hard algorithm such as Argon2id, bcrypt or scrypt. It tempts because salting does defeat rainbow tables, and SHA-256 suits integrity checks and file fingerprinting.

  • ✓

    bcrypt with a per-user salt

    Why this is correct

    bcrypt applies an adaptive, deliberately slow key-derivation function with a tunable cost factor, and the per-user salt ensures identical passwords yield distinct digests, defeating rainbow-table and precomputation attacks. This directly satisfies the stem's requirement for secure password storage, unlike fast general-purpose hashes such as SHA-256.

  • ✗

    MD5 with a static salt

    Why it's wrong here

    MD5 is cryptographically broken with practical collision attacks, and a static salt shared across accounts lets one cracking effort compromise every identical password simultaneously. It tempts because salting conceptually addresses precomputed tables, and MD5 remains acceptable for non-security checksums such as verifying file transfers.

  • ✗

    Base64 encoding

    Why it's wrong here

    Base64 is reversible encoding, not hashing, so anyone with database access can decode every password instantly. It is tempting because it obscures plaintext visually and is used for transporting binary data, and would be correct when encoding certificates or API payloads, not for credential storage.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.