- Home
- All questions
- Question 533
CompTIA Security+ study material · question 533 of 611
A pepper is compromised. Why can it not simply be rotated?
Show the answer
Answer: C. Because changing it requires knowing each user's password, so all affected users must reset
The stored hash mixes the pepper with a password the verifier no longer has, so the value cannot be recomputed.
Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Common requirements for peppering strategies