Courseiva
Attacking Passwords →hardMultiple Choice

GCIH Attacking Passwords Practice Question

Which of the following best explains why 'Rainbow Tables' are less effective against modern systems that implement salted hashes?

⚠ Common exam trap

Candidates often incorrectly assume salts make hashes impossible to crack, rather than understanding that salts specifically break the efficiency of precomputed rainbow tables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Salts negate the precomputed nature of rainbow tables

Rainbow tables are precomputed tables of hashes for all possible plaintext passwords within a specific character set. By adding a random, per-user salt before hashing, the final hash becomes dependent on both the password and the salt. This means an attacker would need to build a new rainbow table for every unique salt, rendering precomputed tables computationally useless.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Salting increases the length of the hash, causing buffer overflows

    Why it's wrong here

    Salting does not cause buffer overflows. Modern hash storage uses fixed-length fields or dynamic storage that handles the extra data. The security benefit comes from the uniqueness added by the salt, not from any memory corruption vulnerability.

  • ✗

    Salts make the total hash space too large to compute

    Why it's wrong here

    The salt does not make the hash space larger; it makes the mapping between plaintext and hash unique to each account. The primary defense is that the attacker cannot use the same precomputed table across multiple users or systems.

  • ✓

    Salts negate the precomputed nature of rainbow tables

    Why this is correct

    Rainbow tables rely on the fact that a specific password always results in the same hash. By appending a salt, the hash calculation changes for each user. An attacker would have to compute a unique table for every single salt, destroying the efficiency of precomputation.

  • ✗

    Salts slow down the hashing algorithm significantly

    Why it's wrong here

    Salting adds negligible time to the hashing process. The performance hit comes from using slow, compute-intensive algorithms like bcrypt or Argon2, not from the addition of a few bytes of salt data to the input string before the hashing function executes.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.