- Home
- All questions
- Question 158
CompTIA Security+ study material · question 158 of 611
An administrator raises the password hashing work factor until each login takes three seconds. What new risk has been introduced?
Show the answer
Answer: D. The login endpoint becomes a denial-of-service vector through CPU exhaustion
A work factor is a balance: too high and an attacker floods the login endpoint to exhaust the server's CPU.
Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Using Work Factors