Which technique adds complexity before a one-way hash function?

Which of the following is used to add extra complexity before using a one-way data transformation algorithm?

  1. Key stretching
  2. Data masking
  3. Steganography
  4. Salting Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests precise knowledge of when and why random data is introduced into a hashing pipeline, with the common trap being confusion between input augmentation (salting) and computational cost enhancement (key stretching).

This question evaluates understanding of cryptographic preprocessing techniques used to secure stored credentials. Community consensus strongly supports salting, as it randomly augments input data prior to hashing to neutralize precomputed lookup attacks.

Test-takers often incorrectly choose Key stretching or Steganography. They misinterpret extra complexity as either increasing processing time (key stretching) or concealing information within media (steganography), overlooking that salting specifically modifies the plaintext input to guarantee unique hash outputs.

Community Discussion (18 comments)

lauren2wright 👍 17
D. Salting Salting involves adding random data to the input of a one-way hash function to ensure that the same input will produce different hash values, thus making it more difficult for attackers to use precomputed hash tables (rainbow tables) to reverse engineer the original input.
JackExam2025 👍 3 Selected: D
Salting is primarily used to ensure that even if two users have the same password, their hashes will differ due to the unique random salt added to each password before hashing. This helps prevent attacks like rainbow table attacks, where precomputed hash values are used to reverse the hash back to the original password.
23711ec 👍 1 Selected: D
correct answer
Hasss 👍 1 Selected: C
The extra complexity added before a one-way data transformation algorithm is salting,
AryzBeats 👍 1 Selected: D
Salting is used to add complexity to the input of a one-way hash
Laraa 👍 2 Selected: D
Salting is a technique used to add extra complexity to data, such as passwords, before applying a one-way transformation algorithm like hashing. The salt is a random value that is combined with the input data (e.g., a password) to produce a unique output even if the input data is the same. This process prevents attacks such as rainbow table attacks and ensures that identical inputs do not result in identical hashes.
SHAGZZ 👍 1 Selected: D
salting in simpler terms is adding a random character before performing the hash(one way function algorithm)
way12 👍 1 Selected: C
salting is used to enhance further security. salt is added to the input data before hashing
JRCHENRY 👍 1 Selected: D
Salting is used to add extra complexity before using a one-way data transformation algorithm.
88d4601 👍 1 Selected: C
Salting
buzzor 👍 1
salting is adding of random data to an existing hash to in order to increase the integrity of the hash by then performing a hash function producing hash values. it is used to prevent rainbow table attack (using precomputed hash tables).
ermahasra 👍 4 Selected: D
D. Salting In the context of CompTIA Security+, salting is a technique used to enhance the security of stored passwords. It involves adding a random value, known as a "salt," to a password before hashing it. This process helps to prevent various types of attacks, such as rainbow table attacks and certain brute-force attacks.
[Removed] 👍 2 Selected: D
D. Salting Salting is used to add extra complexity before using a one-way data transformation algorithm, such as a hash function. Salting involves adding a unique, random value to the input data before it is processed by the hash function, making it more resistant to certain types of attacks like rainbow table attacks.
Lanka22 👍 1 Selected: D
Salting
oluabi.salami 👍 1 Selected: D
D. Salting
MAKOhunter33333333 👍 4 Selected: D
Key stretching is used for weak keys, it will hash the pw, then hash that, then hash the hash of the hash and so forth. Makes the cracking process longer for the attacker Salting is adding random or unique extra character to the password so when cracked it is not the actual PW the attacker thinks
An381038 👍 1 Selected: D
D. Salting
shady23 👍 1 Selected: D
D. Salting

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Cryptographic Preprocessing & Hashing Fundamentals

In modern security architectures, passwords and sensitive data must never be stored in plaintext. Instead, organizations rely on one-way data transformation algorithms (hash functions like SHA-256 or bcrypt) to convert input into a fixed-length digest. However, basic hashing alone is vulnerable to dictionary and precomputed attacks. To mitigate this, a randomized value called a salt is appended or prepended to the original data before the hash function processes it.

Why Salting is the Correct Answer

As highlighted by multiple community experts, salting ensures that identical inputs produce entirely different hash outputs. When a system authenticates a user, it retrieves the stored salt, combines it with the entered password, and hashes the result for comparison. This approach effectively neutralizes rainbow table attacks, which rely on precomputed hash-to-password mappings. Commenters consistently note that salting adds necessary entropy to the input phase, making brute-force and lookup attacks computationally prohibitive.

Analyzing the Distractors

  • Key stretching (Option A) does increase computational complexity, but it focuses on slowing down the hashing algorithm itself (e.g., PBKDF2, Argon2) rather than modifying the input data beforehand. It addresses time-based attacks, not input collision.
  • Data masking (Option B) is a privacy technique that obscures data in non-production environments or UI displays; it does not prepare data for cryptographic hashing.
  • Steganography (Option C) involves hiding secret messages within innocuous files like images or audio. It provides obscurity, not cryptographic integrity or authentication strength, and has no role in the hashing pipeline.

Exam Context & Best Practices

For the SY0-701, recognizing the exact stage where each control applies is critical. Salting operates at the input normalization stage, while key stretching operates during the algorithm execution stage. Mastering this distinction prevents costly errors on performance vs. entropy-related questions.

Official Reference

Exam Strategy

When encountering questions about pre-processing or adding complexity before hashing, immediately look for salting or pepper. Always map the control to its exact position in the data flow pipeline to avoid confusing input modification with computational slowdowns or output encryption.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide