GCIH Attacking Passwords Practice Question
Which of the following best explains why 'Rainbow Tables' are less effective against modern systems that implement salted hashes?
⚠ Common exam trap
Candidates often incorrectly assume salts make hashes impossible to crack, rather than understanding that salts specifically break the efficiency of precomputed rainbow tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Salts negate the precomputed nature of rainbow tables
Rainbow tables are precomputed tables of hashes for all possible plaintext passwords within a specific character set. By adding a random, per-user salt before hashing, the final hash becomes dependent on both the password and the salt. This means an attacker would need to build a new rainbow table for every unique salt, rendering precomputed tables computationally useless.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Salting increases the length of the hash, causing buffer overflows
Why it's wrong here
Salting does not cause buffer overflows. Modern hash storage uses fixed-length fields or dynamic storage that handles the extra data. The security benefit comes from the uniqueness added by the salt, not from any memory corruption vulnerability.
- ✗
Salts make the total hash space too large to compute
Why it's wrong here
The salt does not make the hash space larger; it makes the mapping between plaintext and hash unique to each account. The primary defense is that the attacker cannot use the same precomputed table across multiple users or systems.
- ✓
Salts negate the precomputed nature of rainbow tables
Why this is correct
Rainbow tables rely on the fact that a specific password always results in the same hash. By appending a salt, the hash calculation changes for each user. An attacker would have to compute a unique table for every single salt, destroying the efficiency of precomputation.
- ✗
Salts slow down the hashing algorithm significantly
Why it's wrong here
Salting adds negligible time to the hashing process. The performance hit comes from using slow, compute-intensive algorithms like bcrypt or Argon2, not from the addition of a few bytes of salt data to the input string before the hashing function executes.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.