🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A development team stores user API secrets in Amazon DynamoDB as fixed-length digests so the plaintext values are never written to disk. Today they hash each secret once with SHA-256, but a security review points out the design is still vulnerable to rainbow-table attacks if the table is leaked. Which change will MOST effectively mitigate this specific risk while keeping the stored digest roughly the same 256-bit size?

  • Hash every secret twice-first with SHA-1 and then with SHA-256-before storing the final digest

  • Compress each secret with gzip and hash the compressed output using SHA-256

  • Encrypt each secret with an AWS KMS symmetric customer managed key before writing it to DynamoDB

  • Concatenate a cryptographically secure random value to each secret and then hash the combined value with SHA-256 before storing it

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot