- Home
- All questions
- Question 535
CompTIA Security+ study material · question 535 of 611
An organisation must use FIPS-140 validated implementations. Which password hashing algorithm should it choose?
Show the answer
Answer: B. PBKDF2 with HMAC-SHA-256
PBKDF2 is the one with FIPS-validated implementations available, which is why the compliance requirement selects it.
Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › PBKDF2