GSEC Cryptography Application Practice Question
A security engineer is selecting a hash function to protect stored user passwords in a new application. The threat model assumes an attacker who steals the password database and has substantial GPU resources for offline cracking. Which choice best addresses this threat?
⚠ Common exam trap
The trap here is assuming that salting or iterating a fast general-purpose hash like SHA-256 is sufficient, when only a memory-hard function meaningfully raises the cost of GPU-accelerated offline cracking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A memory-hard password hashing function such as Argon2id with a tuned memory cost, time cost, and parallelism, plus a unique per-user salt.
Password storage needs a deliberately slow, memory-hard function so each offline guess is expensive and GPU parallelism is blunted. Argon2id with tuned parameters and unique per-user salts achieves this, whereas fast hashes, reversible encryption, and a single global secret all fail against an attacker with stolen data and strong cracking hardware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A memory-hard password hashing function such as Argon2id with a tuned memory cost, time cost, and parallelism, plus a unique per-user salt.
Why this is correct
Argon2id is purpose-built for password storage and its memory-hard design sharply limits GPU parallelism, because each guess requires substantial memory that GPUs cannot multiply cheaply. Tuned time and memory costs plus unique per-user salts make offline cracking of a stolen database far more expensive than with fast general-purpose hashes.
- ✗
HMAC-SHA-1 keyed with a single global application secret, because the secret prevents attackers from computing hashes without it.
Why it's wrong here
A single global secret is a key; if the database is stolen and the secret leaks or is brute-forced, all passwords fall at once, and SHA-1 is weakened by known collision attacks. A global key also lets one successful compromise expose every account, unlike per-user salted password hashing.
- ✗
SHA-256 applied twice to each password with a per-user salt, because iterating a fast hash twice doubles the attacker's work.
Why it's wrong here
SHA-256 is designed for speed, so even salted double hashing is trivial for GPUs that compute billions of hashes per second. Doubling the work from one to two iterations barely changes the attacker's cost, so stolen password databases remain feasible to crack offline.
- ✗
AES-256 in CBC mode encrypting each password with a key stored in the same database, because encryption hides the password values.
Why it's wrong here
If the encryption key resides with the database, an attacker who steals the database also steals the key and can decrypt every password immediately. Encryption is reversible by design, whereas password storage needs a one-way function, so this provides no protection against the stated threat.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.