GCIH Understanding Passwords Practice Question
A security administrator is configuring a new web application and wants to implement a password hashing scheme that includes a pepper. Where should the pepper be stored to provide the intended security benefit?
⚠ Common exam trap
The trap here is thinking that storing the pepper in a separate column of the same database is sufficient, but the database compromise would expose both the hashes and the pepper.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In a configuration file on the application server, outside the database.
The pepper must be stored separately from the password hashes to be effective. If the database is compromised but the pepper is stored on the application server in a configuration file, the attacker cannot crack the hashes without also gaining access to that file. This separation provides an additional layer of defense. Storing the pepper in the database or client-side negates its benefit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
In the same database table as the password hashes, but in a separate column.
Why it's wrong here
Storing the pepper in the same database as the hashes defeats its purpose. If the database is compromised, the attacker obtains both the hashes and the pepper, allowing them to crack the passwords as if no pepper were used. The pepper must be stored separately from the hashes to provide an additional layer of security.
- ✗
In the user's browser as a cookie to ensure uniqueness per session.
Why it's wrong here
Storing the pepper in a client-side cookie is insecure because the user can modify or delete it, and it would be exposed to the user and potentially to attackers. The pepper must be a server-side secret that is not accessible to users. Client-side storage is never appropriate for a pepper.
- ✓
In a configuration file on the application server, outside the database.
Why this is correct
A pepper is a secret value added to the password before hashing, and it should be stored separately from the password hashes, typically in a configuration file or hardware security module (HSM) on the application server. This way, even if the database is breached, the attacker cannot crack the hashes without also obtaining the pepper. Storing it outside the database provides defense in depth.
- ✗
In the source code of the application, hardcoded as a constant.
Why it's wrong here
Hardcoding the pepper in source code is a poor practice because anyone with access to the code repository can discover it. If the code is leaked or open source, the pepper is compromised. While better than storing in the database, it is still not ideal; a configuration file or HSM is preferred. However, the question asks for the intended security benefit, which is separation from the database. Hardcoding is less secure than a separate configuration file.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.