Courseiva

GIAC Certified Incident Handler (GCIH) — Questions 301–322

322 questions total · 5pages · All types, answers revealed

Page 4

Page 5 of 5

301
MCQhard

Which of the following best explains why 'Rainbow Tables' are less effective against modern systems that implement salted hashes?

A.Salting increases the length of the hash, causing buffer overflows
B.Salts make the total hash space too large to compute
C.Salts negate the precomputed nature of rainbow tables
D.Salts slow down the hashing algorithm significantly
AnswerC

Rainbow tables rely on the fact that a specific password always results in the same hash. By appending a salt, the hash calculation changes for each user. An attacker would have to compute a unique table for every single salt, destroying the efficiency of precomputation.

Why this answer

Rainbow tables are precomputed tables of hashes for all possible plaintext passwords within a specific character set. By adding a random, per-user salt before hashing, the final hash becomes dependent on both the password and the salt. This means an attacker would need to build a new rainbow table for every unique salt, rendering precomputed tables computationally useless.

Exam trap

Candidates often incorrectly assume salts make hashes impossible to crack, rather than understanding that salts specifically break the efficiency of precomputed rainbow tables.

302
MCQmedium

Which of the following describes the primary danger of an Insecure Deserialization vulnerability in a web application?

A.The vulnerability enables unauthorized database password decryption.
B.It allows attackers to inject malicious code into the database.
C.It facilitates the execution of arbitrary code via gadget chains.
D.It causes the application to leak internal memory structures.
AnswerC

Attackers can craft malicious serialized objects that, when deserialized, trigger a sequence of method calls known as gadget chains. These chains utilize existing application code to perform unintended actions, leading to full remote code execution. This makes it a high-severity risk in applications that accept serialized data from users.

Why this answer

Insecure deserialization occurs when untrusted data is used to abuse the logic of an application, inflict a DoS, or execute arbitrary code. By manipulating the serialized object, an attacker can modify application state, bypass authentication, or leverage existing application code (gadget chains) to gain remote code execution. This is critical because modern frameworks often automatically deserialize objects from user-provided data without sufficient verification or integrity checks on the source.

Exam trap

Candidates often confuse insecure deserialization with standard injection attacks like SQLi, failing to recognize that the core danger specifically stems from abusing application logic and leveraging gadget chains to achieve arbitrary code execution.

303
MCQhard

During a network investigation, an incident responder notices a high volume of outbound DNS queries to a single external domain, with each query containing a long, random-looking subdomain. The queries occur at regular intervals of approximately 30 seconds. Which type of attack is most likely indicated?

A.DNS tunneling for data exfiltration
B.DNS amplification attack
C.DNS cache poisoning
D.Fast flux DNS
AnswerA

DNS tunneling for data exfiltration encodes data in DNS queries and responses, often using long, random-looking subdomains to carry the payload. The high volume and regular interval indicate automated beaconing or data transfer. This method bypasses many firewalls because DNS is often allowed outbound, making it a stealthy exfiltration channel.

Why this answer

The combination of high volume, long random subdomains, and regular intervals strongly suggests DNS tunneling for data exfiltration. Attackers use this technique to encode stolen data into DNS queries, which are often allowed through firewalls. The regular interval indicates automated beaconing or a scheduled exfiltration process.

Other DNS-based attacks like cache poisoning or amplification would present different traffic patterns, such as spoofed source IPs or redirection of legitimate queries.

Exam trap

The trap here is confusing DNS tunneling with fast flux; fast flux changes IP addresses rapidly but does not involve encoding data in subdomains, and it typically does not generate such a high volume of queries from one host.

304
MCQhard

Which of the following describes an 'LLM Hallucination' in the context of analyzing an unknown binary?

A.The model successfully deobfuscates the binary and identifies a buffer overflow.
B.The model generates a convincing but false explanation of a function's purpose.
C.The model refuses to analyze the binary due to safety policy violations.
D.The model correctly identifies the compiler used to build the binary.
AnswerB

Hallucinations often involve the model providing a logical, confident explanation for code that it does not actually understand. In binary analysis, the model may confidently describe a function as a cryptographic routine when it is actually just a simple data copy, leading the analyst to incorrect conclusions.

Why this answer

An LLM hallucination occurs when the model generates confident but factually incorrect information. When analyzing binaries, this manifests as the model identifying non-existent vulnerabilities or describing functions that do not actually exist in the provided code. This is dangerous because it can lead an analyst to waste time chasing false positives or implementing incorrect remediations based on the AI's plausible-sounding but erroneous technical assessment of the binary.

Exam trap

Candidates often mistake 'hallucination' for simple model failure or lack of training data, failing to recognize that the core danger is the model's confidence in generating plausible but entirely false technical details.

305
MCQmedium

A responder is performing a vulnerability scan on a segment containing industrial control systems. Which Nmap timing template should be used to avoid disrupting sensitive, potentially fragile hardware?

A.T0
B.T3
C.T4
D.T5
AnswerA

T0 is the most cautious timing template, sending packets with a very long delay between them. This approach is ideal for critical or fragile environments where even minor network overhead could cause a system failure, ensuring that the scanning process does not disrupt the availability of time-sensitive and mission-critical hardware systems.

Why this answer

Industrial control systems (ICS) and legacy devices are often highly sensitive to high-traffic volumes. Using T0 (paranoid) or T1 (sneaky) ensures that packets are sent at a slow rate, giving these devices sufficient time to process requests. This minimizes the risk of a buffer overflow or service crash that could result from overwhelming the device's limited computational resources with modern scanning speeds.

Exam trap

Candidates often select the default or faster timing templates (like T3 or T4) to save time, ignoring the fact that legacy or sensitive ICS hardware can crash under the stress of rapid scanning.

306
MCQmedium

An incident handler reviews web server logs from an e-commerce application and finds a burst of requests where the JSON body of a POST to /api/v2/orders/checkout contains a deeply nested object several thousand levels deep, causing the backend deserializer to exhaust CPU and memory until the worker crashes. The application accepts arbitrary JSON and binds it directly to internal model objects. Which vulnerability class best describes this attack?

A.Mass assignment through the checkout JSON binding
B.Injection through unvalidated JSON string values
C.Server-side request forgery triggered by the checkout payload
D.Unsafe deserialization of untrusted JSON input
AnswerD

The payload's pathological depth targets the deserializer itself, driving recursive object graph construction until CPU and memory are consumed and the worker dies. Because the application binds arbitrary JSON straight into internal model objects with no depth or size limit, an attacker fully controls the structure parsed, which is exactly the unsafe deserialization condition that turns a normal data-parsing routine into a denial-of-service primitive.

Why this answer

The crash is caused by the deserializer recursively building an extremely deep object graph from attacker-supplied JSON, exhausting CPU and memory. When an API binds untrusted JSON directly to internal models without enforcing maximum depth, size, or allowed-property rules, the parsing stage itself becomes the attack surface. Incident handlers should correlate the crash with payload structure, then recommend depth limits, schema validation, and safe parser configuration.

Exam trap

The trap here is assuming any JSON-related outage must be mass assignment or injection, when the actual mechanism is resource exhaustion inside the deserializer.

307
Multi-Selectmedium

An incident responder is analyzing a compromised Linux server. The attacker gained access via SSH and escalated privileges. The responder wants to identify persistence mechanisms. Which TWO of the following locations should the responder examine? (Choose two.)

Select 2 answers
A.User's ~/.ssh/authorized_keys file
B./etc/hosts
C./etc/passwd
D./etc/crontab and /etc/cron.* directories
E./var/log/auth.log
AnswersA, D

The authorized_keys file contains public keys that are allowed to log in without a password. Attackers often add their own public key to maintain SSH access. Checking this file for unauthorized keys is a critical step in identifying persistence on a compromised Linux system.

Why this answer

The two most common Linux persistence mechanisms are cron jobs and SSH authorized_keys. Cron jobs allow scheduled execution of malicious code, while authorized_keys enables passwordless SSH access. Both are frequently used by attackers to maintain a foothold.

The auth.log, /etc/hosts, and /etc/passwd are not persistence mechanisms; they serve other purposes and may be modified for different attack goals.

Exam trap

The trap here is confusing log files or common configuration files like /etc/passwd with actual persistence mechanisms, when persistence requires a mechanism that automatically re-establishes access.

308
Multi-Selectmedium

An incident handler is reviewing password storage mechanisms after a breach. The attacker exfiltrated a file containing password hashes. Which of the following TWO characteristics would make the hashes more resistant to offline cracking? (Choose two.)

Select 2 answers
A.The password policy requires a minimum length of 8 characters with complexity.
B.Each hash includes a unique, random salt value.
C.The hashes are generated using SHA-256 without any salt.
D.The hashes are generated using a slow key derivation function like bcrypt.
E.The hashes are stored in a compressed archive to save space.
AnswersB, D

A unique salt per password ensures that identical passwords produce different hashes, thwarting rainbow table attacks and forcing attackers to crack each hash individually. Salting also prevents attackers from identifying users with the same password. While salting alone does not slow down each hash computation, it eliminates precomputed attacks and increases the overall effort required to crack a large set of hashes.

Why this answer

The two characteristics that make hashes more resistant to offline cracking are the use of a slow key derivation function (like bcrypt) and the inclusion of a unique random salt per hash. A slow KDF increases the time required to compute each hash, while salting prevents the use of precomputed tables and ensures that identical passwords yield different hashes. Together, they significantly raise the cost for an attacker.

Exam trap

The trap here is confusing password policy strength with hash storage security; a strong password policy helps but does not alter the hash's resistance to cracking.

309
Multi-Selectmedium

During a web application penetration test, an assessor discovers an endpoint vulnerable to OS Command Injection via an improperly sanitized ping utility parameter. Which TWO remediation strategies provide robust defense against command injection vulnerabilities?

Select 2 answers
A.Replace shell execution wrappers with native language libraries or built-in functions designed for the specific task.
B.Apply strict input validation blacklists to filter out dangerous shell operators such as semicolons, pipes, and ampersands.
C.Pass command arguments as separate array elements to process execution functions instead of a single string.
D.Configure the web server process to run with elevated root privileges to ensure access to system binaries.
E.Encode all user inputs using URL encoding standards before passing parameters into system shell execution functions.
AnswersA, C

Native language libraries or built-in functions perform the intended task without invoking a shell, eliminating the command interpreter that enables injection. This satisfies the stem's requirement for robust remediation by removing the vulnerable mechanism entirely, rather than filtering or escaping user input.

Why this answer

Replacing insecure OS command execution functions with native language libraries or APIs completely avoids invoking the underlying operating system shell. When OS execution is strictly necessary, passing arguments as a fixed array rather than a concatenated string prevents shell metacharacter interpretation.

Exam trap

Test-takers often choose input blacklisting of characters like semicolons or pipes, ignoring the fact that attackers easily find alternative shell delimiters.

310
MCQmedium

How can an application distinguish between an authorized user requesting their own profile and an unauthorized user attempting to access a different profile via IDOR?

A.By validating that the user has a session cookie
B.By checking if the resource ID is a valid integer
C.By verifying ownership of the requested resource in the backend
D.By using a CAPTCHA on every request
AnswerC

Verifying ownership is the correct approach to prevent IDOR. The application must check that the currently authenticated user's identifier matches the owner ID of the requested resource. This server-side check ensures that users can only access their own data, effectively blocking unauthorized requests for objects belonging to other users.

Why this answer

The application must correlate the authenticated user's identity (from the session) with the requested resource identifier on the back-end. By checking if the session user owns the requested resource ID before returning data, the application enforces authorization. This moves the logic from 'is this user allowed to access anything?' to 'is this user allowed to access THIS SPECIFIC object?', which is the foundation of secure resource access control.

Exam trap

Test-takers frequently believe that strong session tokens or multifactor authentication alone are sufficient to automatically prevent IDOR without backend code logic changes.

311
MCQmedium

A red team operator is building an LLM-assisted reconnaissance workflow that ingests public DNS records, WHOIS data, and certificate transparency logs, then summarizes potential attack surface for each target. The operator wants to reduce the chance that the model fabricates hostnames that do not exist before the output reaches the engagement report. Which approach best addresses this requirement?

A.Ask the model to include a confidence percentage next to each hostname and discard entries scoring below ninety percent.
B.Switch to a larger parameter model, since increased model size eliminates fabricated hostnames in reconnaissance outputs.
C.Constrain the model to only transform and summarize records supplied in the prompt, and validate extracted hostnames against the original data before reporting.
D.Increase the model's temperature setting so it produces more diverse candidate hostnames for the operator to review manually.
AnswerC

Grounding the model strictly in the supplied DNS, WHOIS, and certificate transparency records removes the opportunity to invent entities, because the task becomes extraction and summarization rather than free generation. Programmatic validation of each hostname against the source data provides a deterministic check that catches any residual fabrication. This combination directly satisfies the requirement of preventing nonexistent hostnames from reaching the engagement report.

Why this answer

Fabricated reconnaissance output is best prevented by restricting the model to extraction and summarization of the records actually provided, then verifying every hostname against those records programmatically. This removes free generation of entities and adds an independent check. Adjusting temperature, trusting self-reported confidence, or relying on a larger model all leave the model free to invent data and provide no deterministic validation against the source records.

Exam trap

The trap here is assuming that a larger model, higher confidence scores, or temperature tuning will fix hallucinated hostnames instead of grounding the task in supplied data and validating against it.

312
MCQmedium

An incident responder notices that a legacy web application stores user credentials using MD5 hashing without salt. Which vulnerability is the primary risk during a credential database compromise?

A.Buffer overflow in the authentication module
B.SQL injection via the login form
C.Precomputed rainbow table attacks
D.Man-in-the-middle interception
AnswerC

Rainbow tables rely on precomputed hash values for common passwords. Because MD5 is fast and unsalted, attackers can pre-calculate hashes for millions of strings. When a database is stolen, they compare the stolen hashes against the table, revealing plaintext passwords in seconds rather than days of brute forcing.

Why this answer

MD5 is cryptographically broken and prone to collision attacks. Without a salt, identical passwords generate identical hashes, enabling precomputed rainbow table attacks. This allows attackers to instantly crack most of the database by comparing hashes against known lists.

Incident responders must prioritize salting and moving to modern algorithms like Argon2 or bcrypt to ensure that stolen credentials cannot be easily reversed, protecting users from credential stuffing attacks elsewhere.

Exam trap

Candidates often focus on the 'MD5' aspect and assume the answer is 'collision attacks'. While MD5 is weak, the specific risk of unsalted hashes in a database is precomputed rainbow table attacks.

313
MCQeasy

A security analyst is reviewing password policies for a Windows Active Directory environment. The current policy requires a minimum length of 8 characters and complexity. However, the organization wants to improve resistance against brute-force attacks. Which of the following changes would most effectively increase the time required for an offline brute-force attack against NTLM hashes?

A.Enable account lockout after 5 failed attempts.
B.Increase the minimum password length to 14 characters.
C.Set the maximum password age to 30 days.
D.Enforce password history of 24 passwords.
AnswerB

Increasing password length exponentially increases the number of possible combinations, making brute-force attacks significantly slower. For NTLM hashes, which are fast to compute, length is the most effective defense. A 14-character password has vastly more entropy than an 8-character one, directly increasing cracking time. This change is the most impactful for resisting offline attacks.

Why this answer

For offline brute-force attacks against NTLM hashes, password length is the most critical factor because it exponentially increases the search space. Other policies like history, age, and lockout are useful for online attacks but do not significantly hinder offline cracking. Thus, increasing the minimum length to 14 characters is the most effective change.

Exam trap

The trap here is focusing on lockout or complexity, but offline attacks ignore lockout and length is the dominant factor in resisting brute-force.

314
MCQeasy

Which of the following is an advantage of using a Key Derivation Function (KDF) like Argon2 over a simple hash like SHA-256?

A.KDFs are faster and improve login performance
B.KDFs are memory-hard and resist GPU cracking
C.KDFs allow for reversible password recovery
D.KDFs require less storage space in the database
AnswerB

Argon2 is a memory-hard KDF, meaning it requires a significant amount of RAM to compute. GPUs have many cores but limited memory per core. This design makes it very difficult for GPUs to parallelize the hashing process, effectively negating their speed advantage and making cracking much slower.

Why this answer

Standard cryptographic hashes like SHA-256 are designed for speed, which is a disadvantage when storing passwords because it allows attackers to test millions of guesses per second. KDFs like Argon2 are specifically designed to be slow and resource-intensive (memory-hard). By forcing the hardware to consume significant memory and time for every single hash calculation, KDFs make large-scale brute-force and dictionary attacks computationally expensive, providing much better security for sensitive credentials.

Exam trap

Candidates often assume KDFs are 'more complex' or 'encrypt the data better'. The primary advantage of KDFs like Argon2 is being 'memory-hard', which forces hardware to use more resources per guess.

315
MCQmedium

During an incident, you capture a suspicious binary that evades static detection. You submit it to an AI-based malware analysis platform, which returns a confidence score of 0.55 and flags 'possible packer.' The binary has not yet been detonated. What should you do next?

A.Submit the binary to a dynamic sandbox and correlate its behavior with network and endpoint telemetry.
B.Close the case as a false positive because the confidence score is below 0.75.
C.Immediately block the file hash across all endpoints based on the AI flag.
D.Extract the binary's strings and import table, then make a final determination based on those static artifacts.
AnswerA

A moderate AI confidence score combined with a packer flag is a hypothesis, not a conclusion. Detonating the sample in a sandbox reveals actual behaviors such as persistence, C2 callbacks, and file system changes, which can be correlated with existing network and endpoint logs. This evidence-based validation is the correct next step before containment or escalation decisions.

Why this answer

An AI confidence score of 0.55 with a packer flag is inconclusive, so the responder must validate the hypothesis with behavioral evidence. Dynamic sandbox detonation exposes the malware's actual actions, which can then be correlated with network and endpoint telemetry to confirm malicious intent. Only after corroboration should containment or escalation occur, avoiding both premature blocking and premature dismissal.

Exam trap

The trap here is assuming a low AI confidence score means the file is benign and can be closed without further analysis.

316
MCQmedium

Which of the following best describes the risk of using 'credential stuffing' against a web application, and how does it differ from a standard dictionary attack?

A.Dictionary attacks use compromised lists; stuffing uses random passwords
B.Stuffing tests leaked credentials; dictionary attacks guess passwords
C.Dictionary attacks are faster than credential stuffing
D.Stuffing targets the database; dictionary attacks target the login
AnswerB

Credential stuffing exploits the human tendency to reuse passwords by automating logins with verified pairs from other breaches. Dictionary attacks are purely probabilistic attempts to guess a password for a single target, making them fundamentally different in execution and success rates.

Why this answer

Credential stuffing uses previously leaked username/password pairs from one service to gain unauthorized access to another. It differs from a dictionary attack because it utilizes valid, known credentials rather than guessing passwords. This is highly effective because users often reuse passwords across multiple sites, making it a critical threat to organizations that do not enforce multifactor authentication (MFA) or monitor for logins from unusual locations.

Exam trap

Candidates often confuse credential stuffing with dictionary attacks, failing to realize that stuffing relies on the reuse of valid leaked credentials rather than brute-forcing new passwords.

317
MCQeasy

Which technique is most effective for preventing prompt injection when integrating an LLM into an automated security orchestration tool?

A.Retraining the model on internal security documentation.
B.Using clear delimiters to differentiate between system instructions and user-supplied data.
C.Encrypting the prompt before sending it to the LLM API.
D.Limiting the LLM context window to 1024 tokens.
AnswerB

Delimiters provide a structural boundary that helps the model categorize input. When system instructions are clearly defined and set apart from user input, the model is significantly less likely to prioritize adversarial input that mimics system-level commands, thereby mitigating the primary vector for successful prompt injection attacks during execution.

Why this answer

Prompt injection occurs when untrusted input is treated as an instruction by the LLM. Implementing structured input validation and separating user input from system instructions is critical. By using delimiters like XML tags or JSON structures to encapsulate user-supplied data, the LLM can clearly distinguish between instructions and data, reducing the likelihood that the model will follow malicious commands embedded within the processed security data or incident reports.

Exam trap

Candidates often rely on simple keyword blacklisting, which attackers easily bypass, failing to implement strict structural separation between instructions and user data.

318
MCQeasy

A security analyst is examining a Linux system that uses shadow password files. The analyst notices that the password hashes are stored in /etc/shadow and are prefixed with $6$. Which of the following best describes the hashing algorithm used for these passwords?

A.MD5
B.SHA-256
C.bcrypt
D.SHA-512
AnswerD

In Linux shadow files, the prefix $6$ denotes the SHA-512 hashing algorithm. This is a common default on many modern Linux distributions. SHA-512 produces a longer hash and is more resistant to brute-force attacks than MD5 or SHA-256, though it is still a fast hash and should be combined with salting and key stretching.

Why this answer

The $6$ prefix in /etc/shadow explicitly indicates the use of SHA-512 for password hashing. This is part of the crypt(3) library format. While SHA-512 is a cryptographic hash function, it is not inherently slow, so it is often used with a salt to prevent rainbow table attacks.

Understanding these prefixes helps incident handlers quickly identify the hashing algorithm in use.

Exam trap

The trap here is confusing the prefix for SHA-256 ($5$) with that for SHA-512 ($6$), or assuming that a high number means a more secure algorithm like bcrypt.

319
MCQmedium

Which of the following scenarios best demonstrates why multi-factor authentication (MFA) is superior to password-only authentication?

A.It makes passwords faster to type for users
B.It eliminates the need for complex passwords
C.It prevents unauthorized access despite password theft
D.It ensures that the password never expires
AnswerC

MFA creates a requirement for a second, separate piece of evidence. If an attacker steals a password, they still lack the second factor (such as a TOTP app or a hardware token). This makes the stolen password insufficient for the attacker to successfully complete the authentication process.

Why this answer

MFA introduces a secondary requirement that is independent of the password. Even if an attacker obtains the password through phishing, credential stuffing, or a database breach, they cannot gain access without the second factor (like a physical security key or a time-based token). This breaks the single point of failure that exists with password-only systems, rendering stolen credentials useless for unauthorized account access, which is the ultimate goal of the adversary.

Exam trap

Test-takers frequently choose options related to encryption or phishing resistance generally, forgetting that the core superiority of MFA lies specifically in defeating stolen password credentials through orthogonal verification factors.

320
MCQeasy

An incident handler is reviewing SMB traffic and notices a large number of SMB2 CREATE requests for files with extensions like .docx, .xlsx, and .pdf, followed by SMB2 WRITE requests that overwrite the same files with encrypted content. The traffic originates from a single workstation and targets a file server. Which type of attack is most likely occurring?

A.Ransomware encrypting files on the file server via SMB.
B.SMB worm propagation, where the attacker is scanning for vulnerable hosts.
C.Data exfiltration through SMB, where files are being copied to an external location.
D.SMB brute-force attack, where the attacker is attempting to guess passwords.
AnswerA

The pattern of opening document files and overwriting them with encrypted content is characteristic of ransomware. SMB is commonly used by ransomware to encrypt files on network shares. The high volume of CREATE and WRITE requests from one workstation to a file server indicates malicious encryption activity.

Why this answer

The correct answer is ransomware encrypting files via SMB. The sequence of opening document files and overwriting them with encrypted data is a hallmark of ransomware. The other options do not match the observed traffic: exfiltration would read files, brute-force would show failed logons, and worm propagation would target multiple hosts.

Exam trap

The trap here is assuming that any SMB file modification is benign; however, overwriting files with encrypted content is a strong indicator of ransomware.

321
MCQmedium

An incident responder investigates a Windows endpoint and discovers an unexpected service running with administrative privileges, executing a binary from an anomalous temporary directory. Reviewing the registry, the responder notices that the service binary path uses a space-separated executable path without surrounding double quotes, and the folder name contains a space. Which post-exploitation persistence and privilege escalation technique has the attacker deployed?

A.DLL search order hijacking involving system directory redirection.
B.Scheduled task modification using legitimate administrator task IDs.
C.Unquoted service path exploitation leveraging Windows path parsing behavior.
D.Windows Management Instrumentation event subscription persistence.
AnswerC

Unquoted service paths occur when service binary paths contain spaces and lack quotation marks. Windows interprets the path sequentially, allowing attackers to place malicious executables in intermediate folders to achieve persistent code execution with elevated privileges.

Why this answer

Unquoted service paths occur when Windows evaluates a service binary path containing spaces without enclosing quotation marks. The operating system sequentially checks executable candidates from left to right, splitting at spaces. Attackers drop malicious payloads in intermediate directories, leading to automatic execution with SYSTEM privileges during service startup.

Exam trap

Candidates often confuse unquoted service paths with DLL hijacking because both involve file path resolution order. However, DLL hijacking targets missing libraries rather than unquoted executable paths with spaces.

322
MCQeasy

A junior incident handler is reviewing password storage practices for a legacy application. The application stores passwords as unsalted MD5 hashes. Which of the following best describes the primary risk introduced by the lack of salting?

A.The MD5 algorithm becomes reversible, allowing attackers to decrypt any hash back to the original password using the public MD5 specification.
B.Without a salt, the hash function runs faster, making brute-force attacks more feasible because the attacker can test more candidates per second.
C.The absence of a salt makes the hashes vulnerable to length extension attacks, allowing an attacker to append data and forge valid hashes.
D.Attackers can use precomputed rainbow tables to quickly reverse hashes for common passwords, and identical passwords produce identical hashes, revealing users who share the same password.
AnswerD

This is correct. Without a salt, the same password always produces the same hash, allowing attackers to use precomputed rainbow tables that map hashes to plaintext. This drastically reduces the time to crack common passwords. Additionally, identical hashes in the database indicate that multiple users have chosen the same password, which can be exploited in credential-stuffing attacks. Salting prevents both issues by ensuring unique hashes even for identical passwords and defeating precomputed tables.

Why this answer

The primary risk of unsalted hashes is that attackers can use precomputed rainbow tables to quickly crack common passwords and that identical passwords yield identical hashes, exposing password reuse. Salting addresses both by making each hash unique and defeating precomputation. MD5 remains irreversible, length extension is a separate issue, and salting does not significantly affect hash speed.

Exam trap

The trap here is confusing the role of salting with that of key stretching, assuming that salting slows down brute-force attacks when its main purpose is to prevent precomputation and hash reuse.

Page 4

Page 5 of 5

All pages