Password Security and Credential Storage

Final Quiz

Connecting to LMS... Progress: in progress

Assessment

1. Why should plaintext passwords never be stored?
2. What is password hashing?
3. Why are salts used?
4. What is a work factor?
5. Why are fast general-purpose hashes poor choices for password storage?
6. Which algorithm is commonly used for modern password hashing?
7. What is a pepper?
8. Why use established password hashing libraries?
9. What is credential stuffing?
10. Why should login attempts be rate limited?
11. Why should password reset tokens be protected?
12. Why might sessions be invalidated after a password change?
13. What should developers check during code review?
14. What is rehashing on login?
15. Which statement best summarizes password storage?