WorksheetsPassword Security and Hashing
Total questions: 34
Worksheet time: 17mins
Why is storing passwords in plaintext considered critically insecure?
Anyone with DB access can view real passwords
Attackers must decode hashes first
Password policies become weaker
It only affects password length
Which method relies on the same secret key for both encryption and decryption?
Asymmetric cryptography
Hash-based encoding
Symmetric cryptography
One-way tokenization
Which system uses mathematically related but distinct keys for encryption and decryption?
Symmetric encryption
Asymmetric encryption
Salted hashing
Block cipher mode
The main security issue with plaintext password storage is that it…
Cannot be validated
Gets automatically salted
Is fully exposed if breached
Requires high computation
Hashing a password results in…
An encrypted version of the password
A reversible cryptographic string
A deterministic one-way output
A compressed password representation
Which characteristic correctly describes a hash function?
It must be reversible with the correct key
It produces unpredictable output for identical inputs
It always generates the same output for the same input
It requires a public–private key pair
Which algorithm belongs to the SHA-2 family?
MD5
SHA-256
AES-256
DES
Which algorithm intentionally includes built-in salting and adaptive work factors?
SHA-1
SHA-256
bcrypt
RSA
Why is hashing alone insufficient for password protection?
Hashes cannot be stored safely
Same passwords produce identical hashes
Hashes grow too large to store
Hashes require encryption keys
Rainbow tables are dangerous because they…
Store encrypted passwords
Generate salts automatically
Contain pre-computed hash values
Erase database hashes
A salt is primarily used to ensure that multiple identical passwords…
Are encrypted using AES
Produce identical hashes
Produce unique hash outputs
Cannot be rehashed
Salting effectively neutralizes which attack method?
Keylogging
Rainbow table attacks
Man-in-the-middle attacks
SQL injection
A proper salt must be…
Short and reused across accounts
Secret like a password
Unique, random, and per-user
Derived from the password
Where should the salt be stored for correct authentication?
Stored separately on another server
Discarded after hashing
Stored alongside the hash
Encrypted with the password
During login, the authentication system…
Decrypts the stored hash
Recomputes hash(password + stored salt)
Generates a new random salt
Retrieves plaintext from encrypted form
If two users choose the same password but have different salts, their hashes will…
Match exactly
Be completely different
Be partially reversible
Become incompatible
Slow hashing algorithms are designed to…
Speed up password verification
Limit hash collisions
Increase attacker cost per guess
Remove the need for salts
Which of the following is a slow, computation-intensive password hashing algorithm?
SHA-1
MD5
bcrypt
AES-128
A strong password should be at least…
8 characters long
12 characters long
4 characters long
6 characters long
Which algorithm should NOT be used for password storage?
bcrypt
MD5
Argon2
PBKDF2
Why is SHA-256 without a salt insecure for password storage?
It is too slow
It allows reversible hashes
It becomes vulnerable to pre-computed attacks
It cannot generate long outputs
Best practice requires storing…
Only the hash
Only the salt
Both salt and hash
Plaintext for backup
Salting prevents…
Password expiration
Duplicate hash values
Hash collisions
Encryption failures
Which algorithm is NOT recommended for modern password security?
Argon2
SHA-1
bcrypt
scrypt
What should be stored in the database for secure authentication?
User password in encrypted form
Hashed password + salt
Only the hash
Only the encrypted password
Bcrypt hashes appear as…
Short readable passwords
Long, random-looking strings
Deterministic encrypted keys
Human-friendly text
A secure hashing algorithm should be…
Fast to compute
Reversible with a private key
Slow and computationally expensive
Independent of the input
Plaintext password exposure in a database breach allows attackers to…
Only guess the password
Directly read real user passwords
Regenerate salts
Decrypt data faster
Which approach is safest for storing user passwords?
MD5 with salt
SHA-256 without salt
bcrypt or Argon2 with per-user salt
Plaintext + encryption
Asymmetric encryption is primarily used for…
Password hashing
Digital signatures and secure exchange
Storing password databases
Generating random salts
Password managers enhance security by…
Storing plaintext securely
Generating strong, unpredictable passwords
Hashing passwords using MD5
Sharing passwords across devices
Which of the following is NOT included in a secure password storage workflow?
Hashing the password
Applying a unique salt
Storing plaintext for reference
Storing salt + hash
A strong password should avoid…
Random characters
Uppercase letters
Dictionary words
Symbols and numbers
Using a single global salt for all users results in…
Reduced storage
Stronger protection
Weaker security
Faster hashing
