Skip to content
ScopefileGet the app

Technique fileCryptography

Symmetric vs asymmetric encryption vs hashing

Symmetric encryption uses one shared secret key and is fast, asymmetric encryption uses a public and private key pair and is slow, and hashing uses no key and cannot be reversed. Which one fits depends on the goal: secrecy, key exchange, integrity or proof of origin.

Exam
312-50
Domain
9 · Crypto
Targets
9

The three families

Keys, reversibility and purpose for each cryptographic family
TraitSymmetricAsymmetricHashing
Keys (differs)One shared secretPublic and private pairNone; HMAC adds a secret
Reversible (differs)Yes, with the same keyYes, with the other key of the pairNo, one-way
Speed (differs)Fast, suits bulk dataSlow, suits small dataFast
Main job (differs)ConfidentialityKey exchange and signaturesIntegrity
Hard part (differs)Getting the key to the other side safelyTrusting that a public key is genuineRetiring weak algorithms in time
Names to know (differs)AES, 3DES, Blowfish, RC4, ChaCha20RSA, Diffie-Hellman, ECC, DSASHA-2, SHA-3; MD5 and SHA-1 are retired

Tinted rows marked ≠: at least one of the 3 differs from the others.

Which tool delivers which property

Security property against the cryptographic tool that provides it on its own
Security property against the cryptographic tool that provides it on its ownSymmetricAsymmetricHashHMACSignatureConfidentialityYesYesNoNoNoIntegrityNoNoYesYesYesAuthenticityNoNoNoYesYesNon-repudiationNoNoNoNoYes

How real systems combine them

Common jobs and the family that does each part
JobWhat does the work
Encrypting a laptop diskSymmetric cipher, key protected by a password or hardware module
Setting up a TLS sessionAsymmetric key agreement, then a symmetric session key for the data
Checking a downloaded fileHash compared with the publisher's value
Protecting a backup archiveSymmetric cipher, with the key held apart from the backup
Issuing a certificateA certificate authority signs the binding of a name to a public key

The distinctions that matter

Hybrid encryption is the pattern behind most of that table: asymmetric cryptography settles a key, and symmetric cryptography does the heavy lifting. A key agreement protocol lets two parties arrive at the same secret without ever sending it, and an asymmetric cipher can also carry a key encrypted to the recipient.

Signatures and encryption use the same key pair in opposite directions. Encryption has to keep a message readable by one party only; a signature has to prove to anyone who checks who produced it. Reason from those two goals and the key roles follow, along with most of Module 20.

Hashing on its own proves only that data did not change, because anyone can recompute a hash. HMAC mixes a secret key into the calculation. Password storage is also a hashing job; the attacks on stored hashes, and the defenses that slow them down, are in password attack types.

Wi-Fi security is a tour of symmetric ciphers, from RC4 to AES, covered generation by generation in WEP vs WPA vs WPA2 vs WPA3.

Pick the right key

State the goal first (secrecy, integrity or proof of origin), then find the tool that delivers it.

Answered 0/9Hits 0

T-01

Which of the following is an example of a symmetric encryption algorithm?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADiffie-Hellman is an asymmetric key agreement protocol used to establish a shared secret, not a symmetric cipher.
  2. BCorrect: AES is a symmetric block cipher, using the same secret key to encrypt and decrypt, and is the current standard for bulk encryption.
  3. CElliptic curve cryptography is asymmetric, using public and private key pairs based on elliptic curve math.
  4. DRSA is asymmetric, relying on a public and private key pair derived from large prime factorization.
T-02

What is the recommended way to store user passwords in a database?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AReversible encryption means anyone who obtains the key can recover every password, so stored passwords should never be decryptable.
  2. BSymmetric encryption is reversible by design, so a stolen or leaked key exposes all user passwords at once.
  3. CPlaintext storage relies entirely on access controls, and a single breach or malicious insider instantly exposes every password in the database.
  4. DCorrect: a unique salt with a slow, purpose-built algorithm such as bcrypt, scrypt or Argon2 defeats rainbow tables and makes offline guessing costly.
T-03

In asymmetric encryption, which key is used to encrypt data that can only be decrypted by the intended recipient?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe recipient's private key decrypts the message, so using it to encrypt would require the sender to hold a secret they should never have.
  2. BEncrypting with the sender's private key creates a signature anyone can verify, not confidentiality.
  3. CCorrect: encrypting with the recipient's public key ensures only the holder of the matching private key can decrypt the message.
  4. DData encrypted with the sender's public key could only be decrypted by the sender, not the intended recipient.
T-04

Which type of encryption method requires multiple keys, with each pair of communicating parties having a unique key?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: symmetric encryption needs a separate shared secret for every pair of parties, so the number of keys grows rapidly as users are added.
  2. BHashing uses no keys at all; it produces a fixed-length digest for integrity checks.
  3. CAsymmetric encryption gives each party one key pair usable with everyone, avoiding a unique key for every pair.
  4. DQuantum key distribution is a way to establish keys, not a classic method defined by unique keys for every pair of parties.
T-05

Which of the following cryptographic protocols is specifically designed for secure key exchange over an insecure channel?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAES encrypts data with a shared symmetric key but does not solve how that key is exchanged.
  2. BSHA-256 is a hash function that produces digests and does not exchange keys.
  3. CCorrect: Diffie-Hellman lets two parties derive a shared secret over an untrusted channel, and ephemeral variants provide forward secrecy.
  4. DTriple DES is a deprecated symmetric cipher that offers no way to exchange keys.
T-06

Which of the following is a property of a secure cryptographic hash function?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: collision resistance means it is computationally infeasible to find two different inputs that produce the same hash.
  2. BSecure hash functions are one-way, so being reversible would defeat their purpose.
  3. CPlain hash functions use no key; adding a key turns them into constructions like HMAC.
  4. DA hash function produces a fixed-length output regardless of input size, such as 256 bits for SHA-256.
T-07

What is the primary purpose of an HMAC (Hash-based Message Authentication Code)?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AKey exchange is handled by protocols like Diffie-Hellman, not by message authentication codes.
  2. BCorrect: an HMAC combines a secret key with a hash so the receiver can confirm the message is unaltered and came from a key holder.
  3. CRandom number generation uses dedicated generators, although HMAC can be a building block inside some of them.
  4. DAn HMAC provides integrity and authenticity but does not hide the message, so it is not encryption.
T-08

What is the primary advantage of Elliptic Curve Cryptography (ECC) over traditional RSA encryption?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: ECC achieves comparable security with much shorter keys, such as a 256-bit curve versus 3072-bit RSA, saving bandwidth and computation.
  2. BRSA also supports digital signatures, so signing ability is not a distinguishing advantage of ECC.
  3. CBoth ECC and RSA are vulnerable to large-scale quantum computers, which is why post-quantum algorithms are being adopted.
  4. DECC is often faster for key generation and signing, but speed is not uniform and the core advantage is shorter keys.
T-09

Alice sends a contract to Bob. Bob must be able to confirm it was not altered, and Alice must not be able to deny later that she sent it. The contract does not need to stay secret. How should the digital signature be created and checked?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AUsing Bob's public key is how you encrypt for confidentiality; anyone could do it, so it proves nothing about Alice as the sender.
  2. BAlice's private key never leaves Alice, so Bob could not verify with it, and signing with a public key proves no identity.
  3. CCorrect: only Alice holds her private key, so a signature verified with her public key proves integrity and gives non-repudiation, not confidentiality.
  4. DA shared secret key gives integrity at best, but either party could create it, so it cannot provide non-repudiation for Alice.

Crypto questions in plain words

Why not encrypt everything with RSA and skip symmetric ciphers?

Asymmetric operations are far slower and handle only small blocks of data. Real protocols use them to settle a key, then switch to a symmetric cipher for the traffic.

Is a hash the same as a checksum?

Both detect change, but a checksum such as a CRC is built for accidental corruption. Anyone who alters data can simply recompute it, so it proves nothing against a deliberate edit.

Where does a certificate come in?

A certificate binds a public key to an identity and is signed by a certificate authority. It answers the asymmetric family's hard part: knowing the public key you hold belongs to the party you think it does.

Sources