What Technique Adds a Random String to a Password Before Hashing?

In order to strengthen a password and prevent a hacker from cracking it, a random string of 36 characters was added to the password. Which of the following best describes this technique?

  1. Key stretching
  2. Tokenization
  3. Data masking
  4. Salting Source Reference Answer

Community Votes

D
71%
A
29%

71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests precise CompTIA terminology regarding password storage mechanisms, with the main trap being confusion between salting (adding randomness to ensure uniqueness) and key stretching (increasing computational cost through iteration).

This question evaluates your understanding of password hardening techniques, specifically distinguishing between salting and key stretching. The community consensus confirms that appending a random string to a password prior to hashing is defined as salting, which primarily defends against precomputed dictionary and rainbow table attacks.

Candidates frequently select Key Stretching because some unofficial study materials loosely describe it as 'lengthening' a password. However, CompTIA strictly defines key stretching as using iterative hashing algorithms to slow down brute-force attacks, not merely appending random characters.

Community Discussion (7 comments)

dbrowndiver 👍 12 Selected: D
Salting is the correct answer because it involves adding a random string to a password before hashing to strengthen security. This technique effectively prevents precomputed hash attacks, making it a critical component of modern password protection strategies.
VincentvdS 👍 1 Selected: D
Salting is correct. Read the difference between Salting and Key Stretching on : https://library.mosse-institute.com/articles/2023/07/key-stretching-and-saltingm.html It explains a lot.
Eracle 👍 2 Selected: A
Why not A? From CompTIA Security+ SY0-601 Certification Guide : "Key stretching is where you append a random set of characters to a password to increase the size of the password and its hash, ensuring that a brute-force attack needs more compute time to crack the password."
_tips 👍 1 Selected: A
Salting Adds a random string of characters, called a "salt", to a password before hashing it. This makes each password unique and prevents attackers from: Using dictionary lookups to see how popular passwords are hashed Guessing the hash function to unlock a database of passwords Key stretching Lengthens the password by iterating the hash of the salted password. This makes it much more difficult for attackers to crack passwords using brute-force or precomputed tables.
chalaka 👍 2 Selected: D
D. Salting Explanation: Salting involves adding a random string (called a salt) to a password before it is hashed to prevent attackers from using precomputed hash databases (like rainbow tables) to crack the password. The random string (in this case, 36 characters) is unique and makes the password significantly harder to guess because it ensures that even if two users have the same password, their hashes will be different.
jsmthy 👍 4 Selected: A
Key stretching techniques are used to make a possibly weak key, typically a password or passphrase, more secure against a brute-force attack by increasing the resources it takes to test each possible key. Salting does not add to the length of the password and does not stop attackers from brute-forcing the key as the salt is added after the password is submitted. Tokenization and Data masking will not prevent brute-force attacks for the same reason. They are processes that don't alter a weak password.
Shaman73 👍 2 Selected: D
D. Salting

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Password Storage Hardening

When securing credentials, systems do not store plaintext passwords. Instead, they apply cryptographic transformations. The scenario describes adding a random string to a password before processing it, which is the textbook definition of Salting.

Why Salting is the Correct Answer

Salting involves generating a unique, random value (the salt) and concatenating it with the user's password before applying a hash function. This ensures that identical passwords produce different hash outputs, effectively neutralizing rainbow table attacks and precomputed hash lookups. As noted in community discussions, the 36-character random string guarantees uniqueness across the database, making offline cracking significantly more resource-intensive.

Why Key Stretching is Incorrect

While both techniques improve password security, their mechanisms differ fundamentally. Key stretching refers to algorithms that intentionally slow down hashing by repeating the process thousands or millions of times (e.g., PBKDF2, Argon2, bcrypt). It does not involve appending a random string to increase length; rather, it increases the computational cost per guess. Confusing the two stems from overlapping goals (hardening passwords) but distinct technical implementations.

Analysis of Distractors

Tokenization replaces sensitive data with non-sensitive equivalents (tokens) that have no exploitable mathematical relationship to the original value, commonly used in payment card industries. Data masking obfuscates specific parts of data for display or testing purposes without altering the underlying storage format. Neither technique applies to password hashing workflows.

Community Clarification

Several users initially questioned whether appending characters constitutes key stretching. CompTIA’s official objectives and industry standards clarify that "appending a random set of characters" aligns exclusively with salting. Key stretching focuses on iteration count and algorithmic complexity, not character addition. Referencing comparative technical articles helps solidify this distinction for exam day.

Official Reference

Exam Strategy

Always map the exact action described in the question to the official CompTIA definition rather than relying on general cybersecurity intuition. If a prompt mentions 'random string,' 'unique value,' or 'prevents rainbow tables,' immediately select Salting. If it mentions 'iterations,' 'delays brute force,' or 'computationally expensive,' choose Key Stretching.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide