Study. uk . com
  1. Home
  2. All questions
  3. Question 537

CompTIA Security+ study material · question 537 of 611

When is the usual moment to re-hash a user's password with an increased work factor?

  1. At the user's next successful login
  2. During the next scheduled maintenance window
  3. Immediately, using the stored hash as input
  4. When the password expires
Show the answer

Answer: A. At the user's next successful login

Only then is the plaintext available to re-hash. Layering over the old hash weakens the result.

Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Upgrading the Work Factor

Challenge yourself on this topic → Study as cards