How to Secure Login Databases Against Breaches?

An organization wants to limit potential impact to its log-in database in the event of a breach. Which of the following options is the security team most likely to recommend?

  1. Tokenization
  2. Hashing Source Reference Answer
  3. Obfuscation
  4. Segmentation

Community Votes

B
76%
D
24%

76% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the critical distinction between reversible and irreversible data protection techniques, with the common trap being the misapplication of network segmentation or reversible encryption to credential storage.

This question evaluates the appropriate cryptographic method for protecting authentication credentials during a data breach. Community consensus strongly favors hashing due to its one-way nature, which renders stolen passwords useless to attackers.

Segmentation is frequently selected because it effectively limits lateral movement and contains breaches; however, it fails to directly protect the actual stored credentials if the database itself is compromised or accessed via application-layer exploits.

Community Discussion (21 comments)

dbrowndiver 👍 7 Selected: B
When passwords are hashed, the database stores only the hash values instead of the actual passwords. This means that even if the database is breached, the attackers cannot easily obtain the original passwords. Hashing is a one-way function, meaning it is computationally infeasible to reverse-engineer the original input from the hash. This ensures that password data is secure even if exposed. Hashing significantly mitigates the risk of credential theft by ensuring that password data remains protected, making it the most effective choice for securing a log-in database against potential breaches. Hashing is the correct answer because it effectively limits the impact of a database breach by storing only hashed versions of passwords, thereby protecting sensitive credential information. Hashing ensures that even if the log-in database is compromised, the passwords remain secure and difficult for attackers to reverse-engineer.
35f7aac 👍 6
Why not C? What if they do get the data? Data obfuscation is the process of disguising confidential or sensitive data to protect it from unauthorized access. Data obfuscation tactics can include masking, encryption, tokenization, and data reduction. Data obfuscation is commonly used to protect sensitive data such as payment information, customer data, and health records.
9149f41 👍 1 Selected: B
When a network is breached, segmentation makes other parts of the network safer. However, gaining access to the database by breaking the log-in password will not be of any assistance. Instead, password hashing makes it more difficult for hackers to crack.
braveheart22 👍 1 Selected: D
The correct answer is D. This is because, referencing the CompTIA study guide, Segmentation is a method of securing data by dividing networks, data, and applications into isolated components to improve sensitive data protection, limit the impact of a breach, and improve network security
deejay2 👍 1 Selected: D
Segmentation. It deals with seperating the data, to store in different locations, to make it harder for the attacker during a breach.
Xezita 👍 1
A - It talks about limiting the potential impact.
deejay2 👍 2
D is the answer
Ty13 👍 2 Selected: B
B. Hashing Use Tokenization for payments and credit cards - the data needs to be retrievable, so you'd replace the sensitive info (your CC numbers) with a non-sensitive token to act as a dummy. If you use Apple/Android Pay, the CC you save on your phone is tokenized so the actual numbers can't be stolen. Hashing is for log-in databases and such where you need to secure the info.
RIDA_007 👍 1
The answer is Hashing! The key is Log in and hashing is used for Authentication. During login, the system combines the entered password with the stored hashes. If the result matches the stored hash, the login is successful
SpikeyOG 👍 4 Selected: D
The correct answer is segmentation. From the CompTIA study guide, Segmentation is a method of securing data by dividing networks, data, and applications into isolated components to improve sensitive data protection, limit the impact of a breach, and improve network security
nyyankee718 👍 3 Selected: B
log-in database is the key in the question, which is related to hashing
17f9ef0 👍 2 Selected: A
Answer is A
a4e15bd 👍 3
A. Tokenization Here is why: Tokenization replaces sensitive information with token that has no meaningful value outside the tokenization system. The original data is stored securely elsewhere. If the a database with tokenized data is breached, the sensitive information remains protected. Keep in mind, hashing only protects stored passwords which is by converting them into a fixed size string of characters that are irreversible, but what about all the other data that is also stored in a login database like username or emails, security questions and answers, multi factor authentication, account status or last login information. Hashing is not going to protect all that. This is why although hashing is a great choice for securing passwords, it is not the best option considering the context of a login database and hence tokenization is the correct answer!
mr.sgtan 👍 2 Selected: A
For "log-in" database, using tokenization to replace sensitive data with non-sensitive placeholder can secure the log-in data information.
mr.sgtan 👍 1 Selected: D
For "log-in" database, using tokenization to replace sensitive data with non-sensitive placeholder can secure the log-in data information.
Andrewyounan 👍 2 Selected: B
Just for clarification "log-in database" means username and password. Because it took me a minute to process it's not database-SQL
Etc_Shadow28000 👍 3 Selected: B
B. Hashing Hashing is the most likely recommendation for protecting a log-in database. By hashing passwords, the organization ensures that even if the database is breached, the actual passwords are not exposed in plaintext. Hashing converts passwords into a fixed-size string of characters, which is not reversible, thus protecting user credentials. Therefore, the correct answer is: B. Hashing
drosas84 👍 3 Selected: B
If you said anything besides B, you need to go back and hit the books. Keyword in the question is "log-in". What do you use to login? ID and password right? So hashing your ID and password will turn them into a string of nondescript text that cannot be reversed or decoded. Hashing log-in passwords will limit potential impact.
Shaman73 👍 2 Selected: B
B. Hashing
jotanyik 👍 1
A. Tokenization
aed0e20 👍 3
D. Segmentation Segmentation involves dividing a network into smaller, isolated segments to limit the potential impact of a breach. By segmenting the network, the organization can contain the breach within a specific segment, preventing it from spreading to other parts of the network, including the log-in database. This approach helps to minimize the scope of the breach and reduce the likelihood of unauthorized access to sensitive data.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Credential Storage Best Practices

When securing a login database, the primary objective is ensuring that stolen credentials cannot be recovered by attackers. This requires a protective mechanism aligned with how authentication systems verify identity.

Why Hashing is Correct

Hashing is the definitive standard for password storage. As highlighted by community experts, hashing transforms plaintext passwords into fixed-length strings using a one-way mathematical function ([Comment 1]). Because reversing the process is computationally infeasible, a breached database yields only unusable hash values. During login, the system hashes the entered password and compares it to the stored hash, enabling secure verification without ever exposing the original secret ([Comment 9]). Modern standards incorporate salting and key stretching to neutralize dictionary and rainbow table attacks.

Why Other Options Fail

  • Tokenization substitutes sensitive data with non-sensitive placeholders, but the original data must remain retrievable for downstream processes, such as banking or payment processing ([Comment 8]). Passwords require zero retrieval capability, making tokenization architecturally mismatched.
  • Obfuscation disguises data or code to hinder analysis, but it relies on concealment rather than cryptographic strength. Techniques like masking or simple encoding are trivially reversible and inadequate for high-value authentication secrets ([Comment 2]).
  • Segmentation isolates network segments or applications to restrict lateral movement and contain incidents ([Comment 4], [Comment 10]). While vital for defense-in-depth, it does not encrypt or scramble the database contents. If an attacker gains direct access to the login database, unhashed passwords remain fully exposed.

Official Reference

Exam Strategy

Always align the protection method with the data's operational requirement: select hashing for non-reversible secrets like passwords, tokenization for retrievable sensitive records like payment tokens, and segmentation for architectural isolation. Scan the question for authentication-specific keywords to immediately eliminate network-level or reversible solutions.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide