- Home
- All questions
- Question 263
CompTIA Security+ study material · question 263 of 611
How must a verifier store passwords so they resist offline attack?
Show the answer
Answer: D. Salted and hashed with a purpose-built password hashing scheme with a tunable cost factor
The cost factor is what makes each guess expensive. A fast hash such as SHA-256 is unsuitable however it is salted.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.1.2 Verifier Requirements