GCIH Understanding Passwords Practice Question
What is the primary function of a salt in password storage?
⚠ Common exam trap
Candidates often mistakenly believe a salt is for encryption or to hide the password from the admin. Its sole purpose is to make each hash unique to prevent precomputed bulk attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To prevent precomputed rainbow table attacks
A salt is a random value added to a password before hashing. Its purpose is to ensure that identical passwords produce unique hash results. This prevents attackers from using precomputed tables (rainbow tables) to reverse hashes. By forcing attackers to crack each hash individually, the salt effectively renders bulk cracking attacks against a database computationally infeasible, significantly increasing the time and resources required for a successful offline attack after an initial breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To increase the length of the password string
Why it's wrong here
While a salt does technically increase the length of the input, this is a byproduct rather than the primary goal. The core function is to add entropy and uniqueness to the hashing process, not to simply satisfy password length requirements or storage constraints in a database table.
- ✓
To prevent precomputed rainbow table attacks
Why this is correct
Salts prevent rainbow tables by ensuring that the hash for a password like 'password123' is unique for every user. Because the attacker cannot precalculate the hashes for all possible salts, they cannot use a standard table to crack the stolen database quickly, forcing a much slower brute-force approach.
- ✗
To encrypt the password in the database
Why it's wrong here
Salting is part of a one-way hashing process, not encryption. Encryption is reversible with a key, whereas hashing is meant to be irreversible. The salt is stored alongside the hash, but it does not provide the reversible properties required for true data encryption or secure information recovery.
- ✗
To hide the algorithm type from attackers
Why it's wrong here
Salts do not obfuscate the algorithm used. Attackers can usually infer the algorithm by looking at the hash structure or the application configuration. Security through obscurity regarding the algorithm is not a standard practice; the security should come from the strength of the function and the salt.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.