Courseiva

GPEN Password Attacks and Formats Practice Question

Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?

⚠ Common exam trap

Candidates often confuse salting with hashing algorithms themselves, mistakenly believing that salting makes the hash itself impossible to reverse rather than specifically preventing the use of precomputed rainbow tables for cracking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They prevent the identification of identical passwords.

Salted hashes introduce a unique, random string to the hashing process for every user, ensuring that identical passwords result in different hashes. This makes it impossible to use global rainbow tables. Unsalted hashes are inherently vulnerable to these tables, as the same plaintext always produces the same hash, allowing for near-instant cracking of common passwords across an entire database once a single table is computed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They enable the use of rainbow tables.

    Why it's wrong here

    Salted hashes explicitly prevent the use of precomputed rainbow tables. Rainbow tables rely on the consistency of hash outputs for identical inputs across the entire set. When a unique salt is introduced, the precomputed table would have to be recalculated for every possible salt, making it computationally infeasible.

  • ✓

    They prevent the identification of identical passwords.

    Why this is correct

    With a unique salt per entry, two users with the same password will have completely different hashes stored in the database. This obscures the fact that they are using the same password, which is a major security benefit when a database is compromised, as attackers cannot easily spot patterns.

  • ✗

    They are inherently faster to crack than unsalted hashes.

    Why it's wrong here

    Salted hashes are actually harder to crack than unsalted ones because they force an attacker to perform a unique attack for every single user record. There is no performance gain for the attacker; in fact, the overhead of handling the salt adds a small, albeit negligible, amount of complexity.

  • ✓

    They require the salt to be known for successful cracking.

    Why this is correct

    To verify a guess against a salted hash, the attacker must know the specific salt used. Without the correct salt, the candidate password will generate a different hash than the stored one. Therefore, the salt must be extracted from the database alongside the hash to perform any cracking.

  • ✗

    They are usually stored in cleartext in the configuration file.

    Why it's wrong here

    Salts are not secrets and are typically stored alongside the hash in the database. While they are not 'secret', they are not stored in cleartext in a configuration file; rather, they are part of the stored credential record, allowing the system to re-compute the hash during login verification.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.