Courseiva
Understanding Passwords →mediumMultiple Select

GCIH Understanding Passwords Practice Question

Which TWO of the following are considered best practices for password hashing to mitigate offline cracking?

⚠ Common exam trap

Candidates often include 'using a strong encryption algorithm' like AES, which is irrelevant for hashing, as hashing is a one-way function, not encryption, and does not provide protection against offline cracking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a unique, random salt for every user

Modern password storage must prioritize computational cost and uniqueness. Using a per-user salt ensures that even identical passwords result in different hashes, preventing rainbow table attacks. Increasing the computational work factor (e.g., iterations) forces attackers to spend more CPU time per guess, making massive brute-force efforts prohibitively expensive. These controls are foundational to defense-in-depth, protecting user data integrity even when the authentication database is successfully exfiltrated by a threat actor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a unique, random salt for every user

    Why this is correct

    A unique salt ensures that two users with the same password have different hash outputs. This effectively neutralizes precomputed rainbow table attacks because the attacker would need to generate a new table for every unique salt value, which is computationally impossible for large user databases.

  • ✗

    Use a global static pepper appended to all hashes

    Why it's wrong here

    A global pepper adds security, but it is not a primary best practice compared to unique salting. If the application source code is compromised, the static pepper is often discovered, rendering the protection ineffective. It is an additional layer, but not a replacement for cryptographically sound individual salting.

  • ✓

    Employ a high-cost key derivation function

    Why this is correct

    Functions like Argon2, bcrypt, or scrypt are designed to be computationally expensive. By adjusting the work factor, organizations can increase the time required to hash a password, significantly slowing down offline cracking attempts. This forces attackers to invest massive hardware resources for relatively little gain in speed.

  • ✗

    Truncate passwords to 8 characters to save space

    Why it's wrong here

    Truncating passwords significantly reduces the entropy and search space for attackers. A shorter password is exponentially faster to crack than a longer one. Best practices dictate allowing long, complex passwords rather than limiting length, as entropy is the best defense against both online and offline guessing.

  • ✗

    Store hashes in plain text for performance

    Why it's wrong here

    Storing hashes in plain text is a critical security failure. If the database is compromised, the attacker has immediate access to every credential without needing to perform any cracking. Hashing must be performed to provide a one-way transformation, and it should never be bypassed for performance reasons.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.