
EC-CouncilCertified Encryption Specialist
Domain 5Objective 2
Rainbow Tables and Password Cracking ECES Practice Questions (Page 3)
Part of the Cryptanalysis domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
9concepts
Questions 11–15
- 11
A security auditor is reviewing a legacy web application that stores user passwords as unsalted MD5 hashes. The auditor warns that an attacker with the hash database could recover many passwords using precomputed rainbow tables. The application team is planning to migrate to a modern framework and wants to prevent this specific attack going forward. Which change most directly addresses the rainbow table risk?
Select an answer first - 12
An analyst is using a rainbow table to crack a hash. The table has a chain length of 5,000. The analyst applies the reduction function to the target hash and gets a value that is not found in the table's endpoints. What should the analyst do next?
Select an answer first - 13
In a rainbow table, what is the role of a reduction function?
Select an answer first - 14
When using a rainbow table to crack a hash, what is the first step after receiving the target hash?
Select an answer first - 15
What is the main advantage of a rainbow table over brute-force password cracking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.