Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Password Security and Hashing

Total questions: 34

Worksheet time: 17mins

Name
Class
Date
1.

Why is storing passwords in plaintext considered critically insecure?

a)

Anyone with DB access can view real passwords

b)

Attackers must decode hashes first

c)

Password policies become weaker

d)

It only affects password length

2.

Which method relies on the same secret key for both encryption and decryption?

a)

Asymmetric cryptography

b)

Hash-based encoding

c)

Symmetric cryptography

d)

One-way tokenization

3.

Which system uses mathematically related but distinct keys for encryption and decryption?

a)

Symmetric encryption

b)

Asymmetric encryption

c)

Salted hashing

d)

Block cipher mode

4.

The main security issue with plaintext password storage is that it…

a)

Cannot be validated

b)

Gets automatically salted

c)

Is fully exposed if breached

d)

Requires high computation

5.

Hashing a password results in…

a)

An encrypted version of the password

b)

A reversible cryptographic string

c)

A deterministic one-way output

d)

A compressed password representation

6.

Which characteristic correctly describes a hash function?

a)

It must be reversible with the correct key

b)

It produces unpredictable output for identical inputs

c)

It always generates the same output for the same input

d)

It requires a public–private key pair

7.

Which algorithm belongs to the SHA-2 family?

a)

MD5

b)

SHA-256

c)

AES-256

d)

DES

8.

Which algorithm intentionally includes built-in salting and adaptive work factors?

a)

SHA-1

b)

SHA-256

c)

bcrypt

d)

RSA

9.

Why is hashing alone insufficient for password protection?

a)

Hashes cannot be stored safely

b)

Same passwords produce identical hashes

c)

Hashes grow too large to store

d)

Hashes require encryption keys

10.

Rainbow tables are dangerous because they…

a)

Store encrypted passwords

b)

Generate salts automatically

c)

Contain pre-computed hash values

d)

Erase database hashes

11.

A salt is primarily used to ensure that multiple identical passwords…

a)

Are encrypted using AES

b)

Produce identical hashes

c)

Produce unique hash outputs

d)

Cannot be rehashed

12.

Salting effectively neutralizes which attack method?

a)

Keylogging

b)

Rainbow table attacks

c)

Man-in-the-middle attacks

d)

SQL injection

13.

A proper salt must be…

a)

Short and reused across accounts

b)

Secret like a password

c)

Unique, random, and per-user

d)

Derived from the password

14.

Where should the salt be stored for correct authentication?

a)

Stored separately on another server

b)

Discarded after hashing

c)

Stored alongside the hash

d)

Encrypted with the password

15.

During login, the authentication system…

a)

Decrypts the stored hash

b)

Recomputes hash(password + stored salt)

c)

Generates a new random salt

d)

Retrieves plaintext from encrypted form

16.

If two users choose the same password but have different salts, their hashes will…

a)

Match exactly

b)

Be completely different

c)

Be partially reversible

d)

Become incompatible

17.

Slow hashing algorithms are designed to…

a)

Speed up password verification

b)

Limit hash collisions

c)

Increase attacker cost per guess

d)

Remove the need for salts

18.

Which of the following is a slow, computation-intensive password hashing algorithm?

a)

SHA-1

b)

MD5

c)

bcrypt

d)

AES-128

19.

A strong password should be at least…

a)

8 characters long

b)

12 characters long

c)

4 characters long

d)

6 characters long

20.

Which algorithm should NOT be used for password storage?

a)

bcrypt

b)

MD5

c)

Argon2

d)

PBKDF2

21.

Why is SHA-256 without a salt insecure for password storage?

a)

It is too slow

b)

It allows reversible hashes

c)

It becomes vulnerable to pre-computed attacks

d)

It cannot generate long outputs

22.

Best practice requires storing…

a)

Only the hash

b)

Only the salt

c)

Both salt and hash

d)

Plaintext for backup

23.

Salting prevents…

a)

Password expiration

b)

Duplicate hash values

c)

Hash collisions

d)

Encryption failures

24.

Which algorithm is NOT recommended for modern password security?

a)

Argon2

b)

SHA-1

c)

bcrypt

d)

scrypt

25.

What should be stored in the database for secure authentication?

a)

User password in encrypted form

b)

Hashed password + salt

c)

Only the hash

d)

Only the encrypted password

26.

Bcrypt hashes appear as…

a)

Short readable passwords

b)

Long, random-looking strings

c)

Deterministic encrypted keys

d)

Human-friendly text

27.

A secure hashing algorithm should be…

a)

Fast to compute

b)

Reversible with a private key

c)

Slow and computationally expensive

d)

Independent of the input

28.

Plaintext password exposure in a database breach allows attackers to…

a)

Only guess the password

b)

Directly read real user passwords

c)

Regenerate salts

d)

Decrypt data faster

29.

Which approach is safest for storing user passwords?

a)

MD5 with salt

b)

SHA-256 without salt

c)

bcrypt or Argon2 with per-user salt

d)

Plaintext + encryption

30.

Asymmetric encryption is primarily used for…

a)

Password hashing

b)

Digital signatures and secure exchange

c)

Storing password databases

d)

Generating random salts

31.

Password managers enhance security by…

a)

Storing plaintext securely

b)

Generating strong, unpredictable passwords

c)

Hashing passwords using MD5

d)

Sharing passwords across devices

32.

Which of the following is NOT included in a secure password storage workflow?

a)

Hashing the password

b)

Applying a unique salt

c)

Storing plaintext for reference

d)

Storing salt + hash

33.

A strong password should avoid…

a)

Random characters

b)

Uppercase letters

c)

Dictionary words

d)

Symbols and numbers

34.

Using a single global salt for all users results in…

a)

Reduced storage

b)

Stronger protection

c)

Weaker security

d)

Faster hashing