- Home
- All questions
- Question 537
CompTIA Security+ study material · question 537 of 611
When is the usual moment to re-hash a user's password with an increased work factor?
Show the answer
Answer: A. At the user's next successful login
Only then is the plaintext available to re-hash. Layering over the old hash weakens the result.
Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Upgrading the Work Factor