Study. uk . com
  1. Home
  2. All questions
  3. Question 538

CompTIA Security+ study material · question 538 of 611

A team refuses to document which password hashing algorithm it uses, calling it sensitive. What is the correct position?

  1. The algorithm may be disclosed but not its work factor
  2. A correctly configured modern algorithm is safe to disclose
  3. Disclosure is safe only for PBKDF2
  4. The algorithm must be kept secret to prevent targeted cracking
Show the answer

Answer: B. A correctly configured modern algorithm is safe to disclose

Security comes from the cost factor and the salt, not from concealing which well-studied function was chosen.

Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Password Hashing Algorithms

Challenge yourself on this topic → Study as cards