GSEC Cryptography Practice Question
A developer is implementing an application that stores user passwords in a database. Which THREE of the following practices are essential for ensuring the cryptographic security of these stored secrets?
⚠ Common exam trap
Candidates often include legacy algorithms like MD5 or SHA-256 in their selection, failing to realize these are too fast and insecure for modern password storage requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a unique, random salt for every user
Proper password storage requires a unique salt to prevent rainbow table attacks, a high-work-factor key derivation function to slow down brute-force attempts, and a secure hashing algorithm designed for slow computation. These defenses are mandatory because standard cryptographic hashes like MD5 or SHA-256 are too fast, enabling attackers to perform trillions of guesses per second on modern hardware, making the stored hashes vulnerable to rapid offline cracking if the database is leaked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using a unique, random salt for every user
Why this is correct
Salting ensures that two users with the same password have different hashes stored in the database. This prevents attackers from using precomputed rainbow tables to crack multiple accounts simultaneously and forces them to perform a unique attack against each user, drastically increasing the time required for successful password recovery.
- ✓
Using the Argon2id hashing algorithm
Why this is correct
Argon2id is a memory-hard key derivation function that is specifically designed to be resistant to GPU and ASIC-based cracking attempts. Using a modern, slow algorithm like Argon2id is essential for current security, as it forces an attacker to dedicate significant memory and time per password guess attempt.
- ✗
Storing passwords using SHA-256 with no salt
Why it's wrong here
SHA-256 is a general-purpose cryptographic hash that is computationally efficient. Without a salt, the same password will always result in the same hash, allowing attackers to use rainbow tables to crack passwords instantly. This is a critical security vulnerability that renders the password storage mechanism ineffective against common attacks.
- ✓
Applying a high iteration count (stretching)
Why this is correct
Increasing the iteration count, or key stretching, adds computational cost to the hashing process. This makes brute-force attacks significantly slower, providing a massive barrier for attackers while remaining negligible for a legitimate user logging in once. It is a standard defense against high-speed hardware used in credential cracking.
- ✗
Encrypting the database table with AES-128
Why it's wrong here
Encryption is different from hashing. If the server is compromised, the decryption key for the database might also be available to the attacker. Storing hashes that are not reversible is a much safer approach than encryption, which implies that the original password can be recovered with the right key.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.