Study. uk . com
  1. Home
  2. All questions
  3. Question 535

CompTIA Security+ study material · question 535 of 611

An organisation must use FIPS-140 validated implementations. Which password hashing algorithm should it choose?

  1. scrypt
  2. PBKDF2 with HMAC-SHA-256
  3. Argon2id
  4. bcrypt
Show the answer

Answer: B. PBKDF2 with HMAC-SHA-256

PBKDF2 is the one with FIPS-validated implementations available, which is why the compliance requirement selects it.

Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › PBKDF2

Challenge yourself on this topic → Study as cards