How to Secure Login Databases Against Breaches?
An organization wants to limit potential impact to its log-in database in the event of a breach. Which of the following options is the security team most likely to recommend?
Community Votes
76% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the critical distinction between reversible and irreversible data protection techniques, with the common trap being the misapplication of network segmentation or reversible encryption to credential storage.
This question evaluates the appropriate cryptographic method for protecting authentication credentials during a data breach. Community consensus strongly favors hashing due to its one-way nature, which renders stolen passwords useless to attackers.
Segmentation is frequently selected because it effectively limits lateral movement and contains breaches; however, it fails to directly protect the actual stored credentials if the database itself is compromised or accessed via application-layer exploits.
Community Discussion (21 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Credential Storage Best Practices
When securing a login database, the primary objective is ensuring that stolen credentials cannot be recovered by attackers. This requires a protective mechanism aligned with how authentication systems verify identity.Why Hashing is Correct
Hashing is the definitive standard for password storage. As highlighted by community experts, hashing transforms plaintext passwords into fixed-length strings using a one-way mathematical function ([Comment 1]). Because reversing the process is computationally infeasible, a breached database yields only unusable hash values. During login, the system hashes the entered password and compares it to the stored hash, enabling secure verification without ever exposing the original secret ([Comment 9]). Modern standards incorporate salting and key stretching to neutralize dictionary and rainbow table attacks.Why Other Options Fail
- Tokenization substitutes sensitive data with non-sensitive placeholders, but the original data must remain retrievable for downstream processes, such as banking or payment processing ([Comment 8]). Passwords require zero retrieval capability, making tokenization architecturally mismatched.
- Obfuscation disguises data or code to hinder analysis, but it relies on concealment rather than cryptographic strength. Techniques like masking or simple encoding are trivially reversible and inadequate for high-value authentication secrets ([Comment 2]).
- Segmentation isolates network segments or applications to restrict lateral movement and contain incidents ([Comment 4], [Comment 10]). While vital for defense-in-depth, it does not encrypt or scramble the database contents. If an attacker gains direct access to the login database, unhashed passwords remain fully exposed.
Official Reference
Exam Strategy
Always align the protection method with the data's operational requirement: select hashing for non-reversible secrets like passwords, tokenization for retrievable sensitive records like payment tokens, and segmentation for architectural isolation. Scan the question for authentication-specific keywords to immediately eliminate network-level or reversible solutions.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →