Study. uk . com
  1. Home
  2. All questions
  3. Question 158

CompTIA Security+ study material · question 158 of 611

An administrator raises the password hashing work factor until each login takes three seconds. What new risk has been introduced?

  1. Existing hashes can no longer be verified
  2. The salt becomes predictable
  3. Stored hashes become easier to crack
  4. The login endpoint becomes a denial-of-service vector through CPU exhaustion
Show the answer

Answer: D. The login endpoint becomes a denial-of-service vector through CPU exhaustion

A work factor is a balance: too high and an attacker floods the login endpoint to exhaust the server's CPU.

Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Using Work Factors

Challenge yourself on this topic → Study as cards