4.2 Quiz: Authentication

🎯 Quiz Instructions

Answer all 5 questions. Predict your answer before you read the options, then click Check Answer to see the full rationale. Your score appears after the last question. Target: 4 of 5 or better before moving to Lesson 4.3.

00:00

✎ Lesson 4.2 Quiz — Authentication
Question 1 of 5 An Aceshack engineer writes this design note for how the sign-in service will store passwords. Exactly one numbered step is wrong.

  1. Run each password through SHA-256 and keep only the resulting hash.
  2. Generate a few random bits (a salt) for every user and hash them together with that user’s password.
  3. Store each user’s salt beside that user’s hash in the account directory.
  4. At sign-in, hash the submitted password with the stored salt and compare the two hashes.
  5. Also keep the password itself in a recoverable column so the helpdesk can read it back to a locked-out user.

Which choice identifies the flaw and corrects it?
Question 2 of 5 Aceshack’s sign-in portal locks an account after five failed attempts. Separately, an adversary has already copied Aceshack’s user directory, which holds a unique salt and a password hash for every account. Consider the three statements.

  I. The lockout setting will slow the adversary down at the live portal.
  II. The lockout setting will not slow the adversary down while they crack the copied directory.
  III. Because every hash has a unique salt, the copied directory cannot be cracked at all.

Which of the statements are true?
Question 3 of 5 Aceshack raises the minimum password length on its portal from 8 characters to 14 and requires everyone to set a new password. Which attack is LEAST affected by that single change?
Question 4 of 5 Aceshack’s helpdesk labels four sign-in setups as multifactor authentication. Which one is labeled correctly?
Question 5 of 5 The drop-in desktop at Aceshack already enforces a 14-character minimum length, complexity requirements, a 90-day maximum password age and a password history of 24. Overnight its security log records 4,000 failed sign-ins against 40 different accounts from a single address, and no successful sign-in. Which single change to the local policy BEST addresses what that log shows?
0 / 5 Quiz complete — review any missed questions. 4+/5 means you’re ready for Lesson 4.3.
AP Cybersecurity · Unit 4 · Lesson 4.2 · Quiz

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]