Study. uk . com
  1. Home
  2. All questions
  3. Question 459

CompTIA Security+ study material · question 459 of 611

Which defence makes rainbow tables useless against a stolen password database?

  1. A shorter cryptoperiod
  2. A unique salt for each password
  3. Encrypting the database at rest
  4. A longer hash output
Show the answer

Answer: B. A unique salt for each password

With a different salt per password, the attacker would need a separate precomputed table for every account.

Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Salting

Challenge yourself on this topic → Study as cards