General Security Concepts 12% of Exam Lesson 6 of 6

Cryptography Basics: Encryption, Hashing, and How They Protect Data

Avatar Of Mudassir KMudassir K ·Oct 4, 2026 ·23 min read
100% through domain
Cryptography Basics Showing Encryption, Hashing, Keys, And Security Goals For Comptia Security+ Sy0-701
CompTIA Security+ SY0-701 · Domain 1.0 · Lesson 01.6
Cryptography basics · Encryption → hashing → keys → practical protection
What You’ll Learn
  • What cryptography is and how it supports confidentiality, integrity, authentication, and non-repudiation.
  • How encryption converts plaintext into ciphertext and how keys control the transformation.
  • How hashing creates fixed-length digests and why hashing is not encryption.
  • Why salts matter for password storage and why password hashing is different from general data encryption.
  • How symmetric and asymmetric cryptography fit into real-world technologies without confusing their different purposes.
  • How to recognize common cryptography clues in Security+ SY0-701 scenario questions.

What Is Cryptography?

Cryptography is the discipline of using mathematical methods, algorithms, keys, and protocols to protect information and enable trusted digital communication. Depending on the cryptographic function and how it is used, cryptography can support confidentiality, data integrity, source authentication, and non-repudiation.

For Security+ SY0-701, the most important distinction is between encryption and hashing. Encryption is designed to transform readable information into ciphertext so that authorized parties can recover the original information with the appropriate cryptographic key. A cryptographic hash function instead produces a fixed-length digest that represents the input and is designed to be one-way and resistant to collisions.

Core exam rule: Encryption protects confidentiality. Hashing helps verify integrity and supports password protection. A hash is not a ciphertext that can simply be decrypted back into the original data.

The Basic Cryptography Vocabulary

Term Meaning Security+ Clue
Plaintext Readable or usable original data Before encryption
Ciphertext Data after encryption Unreadable without the required key and process
Cryptographic key Secret or public/private cryptographic value used by an algorithm Key security is essential
Hash / digest Fixed-length output representing input data Integrity or password-verification clue
Algorithm The mathematical procedure used for a cryptographic function AES, RSA, SHA-256, and similar names

Encryption: Protecting Data Confidentiality

Encryption transforms plaintext into ciphertext using a cryptographic algorithm and a key. When authorized users or systems possess the appropriate keying material and decryption process, the ciphertext can be transformed back into usable plaintext.

The central security objective is confidentiality. Someone who obtains the encrypted data should not be able to understand the protected content simply by reading the ciphertext. Strong encryption therefore depends not only on the algorithm, but also on secure key management, correct implementation, and appropriate configuration.

Encryption fundamentals showing plaintext ciphertext data at rest data in transit and real-world Security+ examples
Encryption protects confidentiality by transforming plaintext into ciphertext and applying appropriate keying material for authorized recovery.

Data at Rest

Data at rest is information stored on devices or storage systems rather than actively moving across a network. Common examples include laptops, databases, file servers, cloud storage, removable drives, and backups.

Full-disk encryption and database encryption are common examples. Encryption at rest can reduce the impact of a lost laptop or stolen storage device because the underlying data remains protected without the appropriate decryption capability.

Data in Transit

Data in transit is information moving between systems. Examples include web traffic, application-to-server communication, remote access sessions, and data moving across public or private networks.

Technologies and protocols such as TLS and VPNs can use cryptography to protect communications while they travel. The precise cryptographic design varies by protocol, but the Security+ exam clue is straightforward: when the scenario is about keeping information private while it moves, think encryption and confidentiality.

Data at Rest
Stored on laptops, servers, databases, cloud storage, or backups.
Think: full-disk or stored-data encryption.
Data in Transit
Moving between endpoints over a network.
Think: TLS, VPNs, and protected communications.

Hashing: Protecting Integrity and Verifying Data

A cryptographic hash function takes input data and produces a fixed-length output called a hash value or digest. The output depends on the contents of the input, so changing the input should produce a different digest with overwhelming probability when a suitable modern hash function is used.

NIST describes approved cryptographic hash functions in terms of properties such as one-way behavior and collision resistance. SHA-256 is a member of the SHA-2 family and is commonly used to generate message digests that can help detect whether data has changed.

Hashing and salting infographic showing SHA-256 fixed-length digests password protection integrity checking and hashing versus encryption
Hashing creates a fixed-length digest for integrity and verification; salting adds unique input before password hashing to reduce the value of precomputed attack tables.

The Avalanche Effect

A useful hashing property is that a small input change should cause a substantially different digest. For example, changing one character in a downloaded file or message should produce a different hash value. Security tools can compare the expected hash with a newly calculated hash to detect modification or corruption.

Hashing Is Not Encryption

Security+ trap: A cryptographic hash is not a reversible substitute for encryption. Hashing produces a digest for verification; it is not intended to provide a normal decrypt operation that returns the original input.
Property Encryption Cryptographic Hashing
Primary goal Confidentiality Integrity / verification
Output Ciphertext Fixed-length digest
Reversible? Designed for authorized decryption Designed to be one-way
Common examples AES, TLS, VPN encryption SHA-256, file verification, password hashing

Salting and Secure Password Storage

Password storage is a special case. Applications should not normally store user passwords as readable plaintext. Instead, secure password-storage designs use password-hashing functions and a unique salt for each password so that identical passwords do not produce identical stored values.

A salt is a random value combined with a password before the hashing operation. Because each password receives a unique salt, attackers cannot rely as effectively on one precomputed table to match the same password hash across many accounts.

Important distinction: A salt is not a password, not a secret key used for ordinary encryption, and not a replacement for a suitable password-hashing function. Its role is to make password-hash attacks such as precomputed lookup-table attacks more difficult.

Password Hashing vs. General File Hashing

Use Case Goal Typical Consideration
File verification Detect unwanted changes Compare trusted and calculated digests
Password storage Verify a password without storing it in plaintext Use a unique salt and a password-hashing design
Digital signature workflow Bind signed data to integrity and signer identity Hashing is combined with asymmetric signature operations

Symmetric and Asymmetric Cryptography

Security+ expects you to recognize two broad approaches to key usage. Symmetric cryptography uses the same shared secret key for encryption and decryption, while asymmetric cryptography uses a mathematically related public/private key pair.

Symmetric algorithms are generally efficient for protecting large volumes of data. AES is the key example to recognize. Asymmetric cryptography is useful for tasks such as secure key establishment, certificates, and digital signatures. The next lesson covers the differences between symmetric and asymmetric encryption in much greater depth, so for this lesson the key exam distinction is simply shared secret vs. key pair.

Symmetric
One shared secret key
  • Fast and efficient
  • Well suited for bulk data encryption
  • Key distribution must be protected
  • Recognize AES as the major example
Asymmetric
Public + private key pair
  • Supports public-key operations
  • Used in certificates and digital signatures
  • Useful for key establishment
  • Recognize RSA and elliptic-curve technologies as examples

Cryptographic Key Management

Strong cryptography can fail when keys are poorly managed. Key management includes generating, storing, distributing, using, rotating, revoking, and securely destroying cryptographic keys according to the needs of the environment.

Cryptographic key management lifecycle showing generation storage distribution use rotation revocation and destruction
Cryptographic security depends on protecting keys throughout their lifecycle, not simply selecting a strong algorithm.
Generate
Strong random keys
→
Protect
Secure storage and access
→
Use & Rotate
Lifecycle controls
→
Revoke & Destroy
Remove unsafe keys

Why Key Protection Matters

If an attacker obtains a key that protects sensitive information, encryption may no longer provide the expected confidentiality. Key protection therefore involves access controls, secure storage, appropriate permissions, lifecycle management, monitoring, and procedures for compromised or retired keys.

Cryptography and Security Goals

Security Goal Cryptographic Technique Example
Confidentiality Encryption Encrypted laptop storage or TLS traffic
Integrity Hashing / digital signatures File verification or tamper detection
Authentication Certificates and digital signatures Verifying a signed identity or server certificate
Non-repudiation Digital signatures and supporting evidence Signed software or documents

Common Cryptography Mistakes

  • Using encoding instead of encryption — Base64 can make data easier to transport or represent, but it does not provide confidentiality.
  • Using hashing when the data must be recovered — if the original data must later be read, encryption is usually the relevant concept, not a one-way hash.
  • Protecting the algorithm but not the key — key compromise can defeat an otherwise strong cryptographic design.
  • Storing passwords in plaintext — secure systems verify passwords using appropriate password-hashing designs rather than keeping readable password values.
  • Ignoring cryptographic lifecycle management — expired, compromised, or unnecessary keys need appropriate rotation, revocation, or destruction.

Security+ Scenario Strategy

When you see a cryptography question, identify the security objective first. If the scenario needs information to remain unreadable to unauthorized people, think encryption. If it needs a fixed-length fingerprint to detect changes, think hashing. If the scenario discusses passwords, look for salting and password-hashing language. If it discusses signing or proving who created data, think digital signatures and asymmetric cryptography.

Need privacy?
Encryption
→
Need change detection?
Hashing
→
Need password verification?
Salt + password hashing
→
Need signer evidence?
Digital signature

For additional context, review the previous lessons on digital signatures and non-repudiation and the CIA triad . Continue with the Security+ SY0-701 guide hub for the full roadmap.

Practice Questions

10 scenario-based questions — click to reveal each answer and explanation.

Exam Quiz

Article 01.6 — Cryptography Basics Exam Simulation  ·  15 questions  ·  10 minutes

🔐

Cryptography Basics — Exam Simulation

15 MCQ questions covering encryption, hashing, salting, data at rest, data in transit, keys, symmetric and asymmetric cryptography, and common Security+ cryptography traps.

📋

15 Questions

Article 01.6 scope only

⏱️

10 Minutes

~40 sec per question

💡

Instant Feedback

Explanation after each answer

📊

Full Review

Score + all answers at end

Lesson 01.6 — Summary

Cryptography Basics: Encryption, Hashing, and How They Protect Data
Module 01: General Security Concepts  ·  Domain 1.0  ·  12% of Security+ SY0-701

Module 01 · Lesson 01.6 Domain 1.0 — General Security Concepts 12% of SY0-701 Exam

📌 Key Takeaways from Lesson 01.6

Encryption
Plaintext → ciphertext using a cryptographic algorithm and key. Primary goal: confidentiality.
Hashing
Data → fixed-length digest. One-way and useful for integrity verification and related security functions.
Password Security
Unique salt + password-hashing design helps prevent identical passwords from producing identical stored verifier values.
Key Distinction
Encryption is reversible with the appropriate keying process. Hashing is not a normal decryption mechanism.
Concept Primary Purpose Exam Clue
Encryption Confidentiality Keep information unreadable to unauthorized users
Hashing Integrity Detect whether data changed
Salting Password security Unique value added before password hashing
Symmetric Shared secret Same secret key for encryption/decryption
Asymmetric Key pair Public/private keys; signatures and certificates
Key management Lifecycle control Generate, protect, rotate, revoke, destroy

⚡ Exam Tips — Lesson 01.6 Specific

  • “Unreadable to unauthorized users” → think encryption and confidentiality.
  • “Detect changes” or “compare digest” → think cryptographic hashing and integrity.
  • “Same password, different stored values” → think unique salts.
  • “Can we recover the original data?” → encryption is designed for authorized recovery; hashing is not.
  • “Base64 or encoding” → representation change, not confidentiality.
  • “Public/private key pair” → asymmetric cryptography.

⚠️ Common Pitfalls — Lesson 01.6

❌
Hash = encrypted data — Wrong. A hash is a digest, not normal ciphertext.
❌
Base64 = encryption — Wrong. Encoding does not provide confidentiality.
❌
A salt must be secret — Not necessarily. Its main role is to make password-hash attacks harder through unique values.
❌
Strong algorithm means keys do not matter — Wrong. Key protection and lifecycle management are fundamental.

📚 What’s Next in Module 01: General Security Concepts

Continue your Domain 1 study — 5 more Lessons remain in this module

01.7
Symmetric vs Asymmetric Encryption: AES, RSA, and When to Use Each
Compare shared-key and public-key cryptography and practical use cases.
→
01.8
Public Key Infrastructure (PKI): Certificates, CAs, and Trust Chains
Certificates, certificate authorities, trust chains, validation, and lifecycle.
→
01.9
Zero Trust Architecture: Never Trust, Always Verify
Continuous verification, least privilege, segmentation, and assume breach.
→
01.10
Physical Security Controls: Locks, Cameras, Badges, and Access Restrictions
Physical barriers, badges, mantraps, surveillance, and defense in depth.
→
01.11
Security Frameworks Overview: NIST, ISO 27001, CIS Controls Compared
Framework purpose, practical differences, and Security+ review.
→

📋 Complete Security+ SY0-701 Series — 5 Modules · 58 Lessons

01 General Security Concepts (Current Module) 12% 11 Lessons
02 Threats, Vulnerabilities & Mitigations 22% 13 Lessons
03 Security Architecture 18% 11 Lessons
04 Security Operations 28% 13 Lessons
05 Security Program Management & Oversight 20% 10 Lessons

Further Reading and Related Guides

Continue learning on NetworkUstad:

External references:

Avatar Of Mudassir K

Holds a BS in Computer Science with 6+ years of experience writing about technology. Covers AI, cloud computing, web development, and SEO, drawing on hands-on project experience to make advanced topics accessible.