GCIH Understanding Passwords Practice Question
Why does the use of pepper provide additional security for password hashes, and where should it ideally be stored?
⚠ Common exam trap
Many candidates confuse a pepper with a salt, incorrectly believing that a pepper should be stored alongside the password hash in the public database table rather than separately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stored in a separate environment variable; adds an extra layer
A pepper is a secret value added to the password hashing process that is stored separately from the hash, typically in a secure configuration file, environment variable, or Hardware Security Module (HSM). Because the pepper is not stored in the database, an attacker who steals only the database cannot brute-force the hashes, as they lack the pepper. This creates a dual-layer dependency that significantly raises the bar for successful offline cracking attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stored in the same database table; prevents rainbow tables
Why it's wrong here
If the pepper is stored in the same database, it provides no protection against an attacker who gains access to that database. The value of a pepper lies entirely in its separation from the hash. If an attacker has both, they can easily reverse the hashing process.
- ✓
Stored in a separate environment variable; adds an extra layer
Why this is correct
Storing the pepper in a secure, separate location (like an environment variable or HSM) ensures that a database leak alone does not expose the passwords. The attacker would need both the database and access to the server's configuration/environment to have any hope of cracking the hashes.
- ✗
Stored in the application code; ensures performance
Why it's wrong here
Hardcoding a pepper in source code is a major security risk. If the source code is ever pushed to a public repository, the pepper is leaked. It should be managed via secure configuration management or secrets storage, not left inside the application's source code where it is easily discovered.
- ✗
Stored in the user session; ensures unique hashes
Why it's wrong here
Peppers are global secrets used during the hashing process, not per-session values. Storing a pepper in a user session would mean that the hash changes every time the user logs in, which is impossible for verification. The pepper must be a consistent, secret, server-side configuration value.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.