Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

Which of the following is the primary purpose of hashing a password before storing it in a database?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To verify the password without storing it in plaintext

Hashing is a one-way function that converts a password into a fixed-length string. It is used to securely store passwords so that even if the database is breached, the actual passwords are not easily recoverable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To make the password longer and more secure

    Why it's wrong here

    Hashing produces a fixed-length digest, so it does not lengthen the password; length is irrelevant to its purpose. It is tempting because longer passwords resist brute-force guessing, but that is a property of the original credential, not the stored hash, and hashing's actual role is one-way verification.

  • ✓

    To verify the password without storing it in plaintext

    Why this is correct

    Hashing is a one-way transformation, so the stored digest cannot be reversed to recover the original password. At login the system hashes the supplied password and compares digests, verifying authenticity without retaining plaintext. This satisfies the stem's requirement of verification without plaintext storage.

  • ✗

    To compress the password to save storage space

    Why it's wrong here

    Hashes are fixed-length and often larger than short passwords, so storage savings do not occur; compression is reversible and would defeat the one-way property. It is tempting because hashing does reduce arbitrary input to a constant size, which resembles compression, but the goal is irreversible verification, not space efficiency.

  • ✗

    To encrypt the password so it can be decrypted later

    Why it's wrong here

    Hashing is a one-way function with no decryption key, so the original password cannot be recovered; encryption is reversible by design. It is tempting because both transform data into unreadable form, but encryption suits data that must later be read, whereas password storage requires irreversible verification.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.