GSEC Access Control and Password Management Practice Question
What is the primary purpose of Salt in password hashing?
⚠ Common exam trap
Examinees often confuse salts with pepper or general key stretching functions, incorrectly believing that the primary goal is simply to slow down brute-force guessing rather than neutralizing pre-computed lookup tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To prevent the use of rainbow tables
A salt is a unique, random string added to a password before it is hashed. This ensures that even if two users have the same password, their resulting hashes will be different. This prevents attackers from using pre-computed tables, such as rainbow tables, to quickly reverse the hashes of stolen passwords. By forcing attackers to calculate hashes for each individual user, the salt significantly increases the computational cost of brute-force and dictionary attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To shorten the length of the stored hash
Why it's wrong here
Adding a salt actually increases the size of the data stored, not decreases it. The goal is to introduce uniqueness and randomness into the hashing process to thwart dictionary attacks, not to optimize for storage space, which is trivial compared to the security benefits provided by salting.
- ✓
To prevent the use of rainbow tables
Why this is correct
Rainbow tables are pre-computed tables of hashes used to crack passwords quickly. By using a unique salt for every user, the set of possible hashes becomes effectively infinite for any given password, rendering rainbow tables useless because they cannot account for the random salt value injected into the hash function.
- ✗
To increase the complexity of the user's password
Why it's wrong here
Salting happens on the server-side during the hashing process and has nothing to do with the password that the user actually chooses. It is a security control applied to the stored hash, not a requirement for the user's password creation process, which should be managed by separate complexity policies.
- ✗
To facilitate easier password recovery
Why it's wrong here
Salting makes password recovery more difficult if it relies on reverse-engineering the hash, which is exactly the intended security effect. It does not help in providing a 'forgot password' feature, which typically relies on secure email-based reset tokens rather than attempting to recover or decrypt the original user password hash.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.