Which technique adds complexity before a one-way hash function?
Which of the following is used to add extra complexity before using a one-way data transformation algorithm?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests precise knowledge of when and why random data is introduced into a hashing pipeline, with the common trap being confusion between input augmentation (salting) and computational cost enhancement (key stretching).
This question evaluates understanding of cryptographic preprocessing techniques used to secure stored credentials. Community consensus strongly supports salting, as it randomly augments input data prior to hashing to neutralize precomputed lookup attacks.
Test-takers often incorrectly choose Key stretching or Steganography. They misinterpret extra complexity as either increasing processing time (key stretching) or concealing information within media (steganography), overlooking that salting specifically modifies the plaintext input to guarantee unique hash outputs.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Cryptographic Preprocessing & Hashing Fundamentals
In modern security architectures, passwords and sensitive data must never be stored in plaintext. Instead, organizations rely on one-way data transformation algorithms (hash functions like SHA-256 or bcrypt) to convert input into a fixed-length digest. However, basic hashing alone is vulnerable to dictionary and precomputed attacks. To mitigate this, a randomized value called a salt is appended or prepended to the original data before the hash function processes it.Why Salting is the Correct Answer
As highlighted by multiple community experts, salting ensures that identical inputs produce entirely different hash outputs. When a system authenticates a user, it retrieves the stored salt, combines it with the entered password, and hashes the result for comparison. This approach effectively neutralizes rainbow table attacks, which rely on precomputed hash-to-password mappings. Commenters consistently note that salting adds necessary entropy to the input phase, making brute-force and lookup attacks computationally prohibitive.Analyzing the Distractors
- Key stretching (Option A) does increase computational complexity, but it focuses on slowing down the hashing algorithm itself (e.g., PBKDF2, Argon2) rather than modifying the input data beforehand. It addresses time-based attacks, not input collision.
- Data masking (Option B) is a privacy technique that obscures data in non-production environments or UI displays; it does not prepare data for cryptographic hashing.
- Steganography (Option C) involves hiding secret messages within innocuous files like images or audio. It provides obscurity, not cryptographic integrity or authentication strength, and has no role in the hashing pipeline.
Exam Context & Best Practices
For the SY0-701, recognizing the exact stage where each control applies is critical. Salting operates at the input normalization stage, while key stretching operates during the algorithm execution stage. Mastering this distinction prevents costly errors on performance vs. entropy-related questions.Official Reference
Exam Strategy
When encountering questions about pre-processing or adding complexity before hashing, immediately look for salting or pepper. Always map the control to its exact position in the data flow pipeline to avoid confusing input modification with computational slowdowns or output encryption.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →