- What cryptography is and how it supports confidentiality, integrity, authentication, and non-repudiation.
- How encryption converts plaintext into ciphertext and how keys control the transformation.
- How hashing creates fixed-length digests and why hashing is not encryption.
- Why salts matter for password storage and why password hashing is different from general data encryption.
- How symmetric and asymmetric cryptography fit into real-world technologies without confusing their different purposes.
- How to recognize common cryptography clues in Security+ SY0-701 scenario questions.
What Is Cryptography?
Cryptography is the discipline of using mathematical methods, algorithms, keys, and protocols to protect information and enable trusted digital communication. Depending on the cryptographic function and how it is used, cryptography can support confidentiality, data integrity, source authentication, and non-repudiation.
For Security+ SY0-701, the most important distinction is between encryption and hashing. Encryption is designed to transform readable information into ciphertext so that authorized parties can recover the original information with the appropriate cryptographic key. A cryptographic hash function instead produces a fixed-length digest that represents the input and is designed to be one-way and resistant to collisions.
The Basic Cryptography Vocabulary
| Term | Meaning | Security+ Clue |
|---|---|---|
| Plaintext | Readable or usable original data | Before encryption |
| Ciphertext | Data after encryption | Unreadable without the required key and process |
| Cryptographic key | Secret or public/private cryptographic value used by an algorithm | Key security is essential |
| Hash / digest | Fixed-length output representing input data | Integrity or password-verification clue |
| Algorithm | The mathematical procedure used for a cryptographic function | AES, RSA, SHA-256, and similar names |
Encryption: Protecting Data Confidentiality
Encryption transforms plaintext into ciphertext using a cryptographic algorithm and a key. When authorized users or systems possess the appropriate keying material and decryption process, the ciphertext can be transformed back into usable plaintext.
The central security objective is confidentiality. Someone who obtains the encrypted data should not be able to understand the protected content simply by reading the ciphertext. Strong encryption therefore depends not only on the algorithm, but also on secure key management, correct implementation, and appropriate configuration.
Data at Rest
Data at rest is information stored on devices or storage systems rather than actively moving across a network. Common examples include laptops, databases, file servers, cloud storage, removable drives, and backups.
Full-disk encryption and database encryption are common examples. Encryption at rest can reduce the impact of a lost laptop or stolen storage device because the underlying data remains protected without the appropriate decryption capability.
Data in Transit
Data in transit is information moving between systems. Examples include web traffic, application-to-server communication, remote access sessions, and data moving across public or private networks.
Technologies and protocols such as TLS and VPNs can use cryptography to protect communications while they travel. The precise cryptographic design varies by protocol, but the Security+ exam clue is straightforward: when the scenario is about keeping information private while it moves, think encryption and confidentiality.
Stored on laptops, servers, databases, cloud storage, or backups.
Think: full-disk or stored-data encryption.
Moving between endpoints over a network.
Think: TLS, VPNs, and protected communications.
Hashing: Protecting Integrity and Verifying Data
A cryptographic hash function takes input data and produces a fixed-length output called a hash value or digest. The output depends on the contents of the input, so changing the input should produce a different digest with overwhelming probability when a suitable modern hash function is used.
NIST describes approved cryptographic hash functions in terms of properties such as one-way behavior and collision resistance. SHA-256 is a member of the SHA-2 family and is commonly used to generate message digests that can help detect whether data has changed.
The Avalanche Effect
A useful hashing property is that a small input change should cause a substantially different digest. For example, changing one character in a downloaded file or message should produce a different hash value. Security tools can compare the expected hash with a newly calculated hash to detect modification or corruption.
Hashing Is Not Encryption
| Property | Encryption | Cryptographic Hashing |
|---|---|---|
| Primary goal | Confidentiality | Integrity / verification |
| Output | Ciphertext | Fixed-length digest |
| Reversible? | Designed for authorized decryption | Designed to be one-way |
| Common examples | AES, TLS, VPN encryption | SHA-256, file verification, password hashing |
Salting and Secure Password Storage
Password storage is a special case. Applications should not normally store user passwords as readable plaintext. Instead, secure password-storage designs use password-hashing functions and a unique salt for each password so that identical passwords do not produce identical stored values.
A salt is a random value combined with a password before the hashing operation. Because each password receives a unique salt, attackers cannot rely as effectively on one precomputed table to match the same password hash across many accounts.
Password Hashing vs. General File Hashing
| Use Case | Goal | Typical Consideration |
|---|---|---|
| File verification | Detect unwanted changes | Compare trusted and calculated digests |
| Password storage | Verify a password without storing it in plaintext | Use a unique salt and a password-hashing design |
| Digital signature workflow | Bind signed data to integrity and signer identity | Hashing is combined with asymmetric signature operations |
Symmetric and Asymmetric Cryptography
Security+ expects you to recognize two broad approaches to key usage. Symmetric cryptography uses the same shared secret key for encryption and decryption, while asymmetric cryptography uses a mathematically related public/private key pair.
Symmetric algorithms are generally efficient for protecting large volumes of data. AES is the key example to recognize. Asymmetric cryptography is useful for tasks such as secure key establishment, certificates, and digital signatures. The next lesson covers the differences between symmetric and asymmetric encryption in much greater depth, so for this lesson the key exam distinction is simply shared secret vs. key pair.
- Fast and efficient
- Well suited for bulk data encryption
- Key distribution must be protected
- Recognize AES as the major example
- Supports public-key operations
- Used in certificates and digital signatures
- Useful for key establishment
- Recognize RSA and elliptic-curve technologies as examples
Cryptographic Key Management
Strong cryptography can fail when keys are poorly managed. Key management includes generating, storing, distributing, using, rotating, revoking, and securely destroying cryptographic keys according to the needs of the environment.
Why Key Protection Matters
If an attacker obtains a key that protects sensitive information, encryption may no longer provide the expected confidentiality. Key protection therefore involves access controls, secure storage, appropriate permissions, lifecycle management, monitoring, and procedures for compromised or retired keys.
Cryptography and Security Goals
| Security Goal | Cryptographic Technique | Example |
|---|---|---|
| Confidentiality | Encryption | Encrypted laptop storage or TLS traffic |
| Integrity | Hashing / digital signatures | File verification or tamper detection |
| Authentication | Certificates and digital signatures | Verifying a signed identity or server certificate |
| Non-repudiation | Digital signatures and supporting evidence | Signed software or documents |
Common Cryptography Mistakes
- Using encoding instead of encryption — Base64 can make data easier to transport or represent, but it does not provide confidentiality.
- Using hashing when the data must be recovered — if the original data must later be read, encryption is usually the relevant concept, not a one-way hash.
- Protecting the algorithm but not the key — key compromise can defeat an otherwise strong cryptographic design.
- Storing passwords in plaintext — secure systems verify passwords using appropriate password-hashing designs rather than keeping readable password values.
- Ignoring cryptographic lifecycle management — expired, compromised, or unnecessary keys need appropriate rotation, revocation, or destruction.
Security+ Scenario Strategy
When you see a cryptography question, identify the security objective first. If the scenario needs information to remain unreadable to unauthorized people, think encryption. If it needs a fixed-length fingerprint to detect changes, think hashing. If the scenario discusses passwords, look for salting and password-hashing language. If it discusses signing or proving who created data, think digital signatures and asymmetric cryptography.
For additional context, review the previous lessons on digital signatures and non-repudiation and the CIA triad . Continue with the Security+ SY0-701 guide hub for the full roadmap.
Practice Questions
10 scenario-based questions — click to reveal each answer and explanation.
Exam Quiz
Article 01.6 — Cryptography Basics Exam Simulation · 15 questions · 10 minutes
Cryptography Basics — Exam Simulation
15 MCQ questions covering encryption, hashing, salting, data at rest, data in transit, keys, symmetric and asymmetric cryptography, and common Security+ cryptography traps.
15 Questions
Article 01.6 scope only
10 Minutes
~40 sec per question
Instant Feedback
Explanation after each answer
Full Review
Score + all answers at end
Lesson 01.6 — Summary
Cryptography Basics: Encryption, Hashing, and How They Protect Data
Module 01: General Security Concepts
·
Domain 1.0
·
12% of Security+ SY0-701
📌 Key Takeaways from Lesson 01.6
| Concept | Primary Purpose | Exam Clue |
|---|---|---|
| Encryption | Confidentiality | Keep information unreadable to unauthorized users |
| Hashing | Integrity | Detect whether data changed |
| Salting | Password security | Unique value added before password hashing |
| Symmetric | Shared secret | Same secret key for encryption/decryption |
| Asymmetric | Key pair | Public/private keys; signatures and certificates |
| Key management | Lifecycle control | Generate, protect, rotate, revoke, destroy |
⚡ Exam Tips — Lesson 01.6 Specific
- “Unreadable to unauthorized users” → think encryption and confidentiality.
- “Detect changes” or “compare digest” → think cryptographic hashing and integrity.
- “Same password, different stored values” → think unique salts.
- “Can we recover the original data?” → encryption is designed for authorized recovery; hashing is not.
- “Base64 or encoding” → representation change, not confidentiality.
- “Public/private key pair” → asymmetric cryptography.
⚠️ Common Pitfalls — Lesson 01.6
📋 Complete Security+ SY0-701 Series — 5 Modules · 58 Lessons
Further Reading and Related Guides
Continue learning on NetworkUstad:
- Security+ SY0-701 Guide Hub — browse the complete certification lesson series.
- Change Management and Security — review the previous lesson on security-focused change control.
- Non-Repudiation and Digital Signatures — revisit digital signatures and asymmetric cryptography.
- The CIA Triad — revisit confidentiality, integrity, and availability.
External references:
- NIST: Cryptography — foundational terminology.
- NIST: Encryption — plaintext, ciphertext, algorithms, and keys.
- NIST: Cryptographic Hash Function — one-way and collision-resistant properties.
- NIST: SHA-256 — message-digest terminology.



