Courseiva

GSEC Access Control and Password Management Practice Question

What is the primary purpose of Salt in password hashing?

⚠ Common exam trap

Examinees often confuse salts with pepper or general key stretching functions, incorrectly believing that the primary goal is simply to slow down brute-force guessing rather than neutralizing pre-computed lookup tables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To prevent the use of rainbow tables

A salt is a unique, random string added to a password before it is hashed. This ensures that even if two users have the same password, their resulting hashes will be different. This prevents attackers from using pre-computed tables, such as rainbow tables, to quickly reverse the hashes of stolen passwords. By forcing attackers to calculate hashes for each individual user, the salt significantly increases the computational cost of brute-force and dictionary attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To shorten the length of the stored hash

    Why it's wrong here

    Adding a salt actually increases the size of the data stored, not decreases it. The goal is to introduce uniqueness and randomness into the hashing process to thwart dictionary attacks, not to optimize for storage space, which is trivial compared to the security benefits provided by salting.

  • ✓

    To prevent the use of rainbow tables

    Why this is correct

    Rainbow tables are pre-computed tables of hashes used to crack passwords quickly. By using a unique salt for every user, the set of possible hashes becomes effectively infinite for any given password, rendering rainbow tables useless because they cannot account for the random salt value injected into the hash function.

  • ✗

    To increase the complexity of the user's password

    Why it's wrong here

    Salting happens on the server-side during the hashing process and has nothing to do with the password that the user actually chooses. It is a security control applied to the stored hash, not a requirement for the user's password creation process, which should be managed by separate complexity policies.

  • ✗

    To facilitate easier password recovery

    Why it's wrong here

    Salting makes password recovery more difficult if it relies on reverse-engineering the hash, which is exactly the intended security effect. It does not help in providing a 'forgot password' feature, which typically relies on secure email-based reset tokens rather than attempting to recover or decrypt the original user password hash.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.