Skip to article
Security+ study guide

What’s the difference between hashing, encryption, and encoding?

The difference between hashing, encryption, and encoding is what each does to data: hashing creates a one-way digest for comparison, encryption protects data with a key, and encoding changes its format so another system can read it. Choose hashing to check integrity, encryption for confidentiality, and encoding for compatibility.

BE The Best Exam Apps team ·
Share

How do hashing, encryption, and encoding compare?

Hashing supports comparison, encryption protects readable information, and encoding makes data fit a format. They can all change how data looks, so appearance alone tells you very little. The useful question is what the system must do with the result.

A payroll file needs authorised staff to read it later. That points to encryption. A downloaded installer needs to match a trusted digest. That points to hashing. Binary data must travel through a text-only interface. That points to encoding.

Recovering encrypted backups also involves RTO and RPO targets: readable data must be restored in time and from an acceptable recovery point.

Scroll sideways to see every column.

MethodWhat it producesCan you recover the input?Typical use
HashingA digest of the inputNo decryption operationCompare file integrity
EncryptionCiphertextYes, with the right keyProtect stored or transmitted data
EncodingAnother representationYes, using the format rulesRepresent binary as Base64 text

What does a hash actually tell me?

A matching hash tells you the checked data matches the expected digest, assuming the digest came from a trustworthy source. A cryptographic hash takes input of varying sizes and produces a digest of a fixed size for that algorithm. SHA-256, for example, produces 256 bits. NIST’s hashing definition describes this input-to-digest relationship.

You can hash a file again after download and compare the results. If an attacker replaces both the file and the published digest, though, the comparison can still pass. The source of the expected value matters.

A hash doesn’t prove who created a file. Use a digital signature when you also need to verify the signer through a trusted key. Different inputs can theoretically share a digest, called a collision; secure algorithms aim to make finding one impractical. A hash is therefore not a guaranteed unique ID for every possible input.

Checking a file’s origin is separate from checking identity and permissions: a trusted file can still be opened by an account that should have no access.

During an investigation, EDR and SIEM evidence can help connect a changed file with the process and account activity around it.

Checking a download
  1. 01Trusted publisherPublishes an expected digest
  2. 02Your downloaded fileHash it with the same algorithm
  3. 03Compare digestsA mismatch means stop and investigate

Why do passwords use salted hashes?

Passwords use salted, deliberately costly password-hashing schemes so a breach doesn’t directly reveal readable passwords. When you sign in, the service processes your entered password with the stored salt and settings, then compares the result. It doesn’t need to recover the original password.

The salt is a per-password value stored alongside the result. It makes identical passwords produce different stored values and defeats reuse of precomputed tables across salts. It isn’t a secret and doesn’t make a weak password strong.

Fast general-purpose hashes let attackers test guesses quickly. Password-hashing schemes add a work cost, often memory cost too. NIST’s password-verifier guidance calls for salted password hashing with a suitable cost factor.

One-way doesn’t mean impossible to guess. An attacker can process candidate passwords and compare the results. That’s guessing the input, not decrypting the hash.

Password spraying and credential stuffing attack account access in different ways; salted password storage addresses a different part of the risk.

Why doesn’t Base64 protect a secret?

Base64 doesn’t protect a secret because anyone who knows the format can decode it without a secret key. The word cat becomes Y2F0 in Base64. A different-looking value is still the same readable information after decoding.

Base64 is useful when an interface expects text but the data is binary. RFC 4648 specifies common Base-N encodings. URL encoding is another formatting tool: it represents characters in a form suitable for parts of a URL. Neither provides confidentiality.

Encoding also appears around secure data. A certificate, encrypted value or hash may be shown in Base64. The security comes from the cryptographic operation inside, not the outer text format.

Recognising secure protocols and their ports helps you tell a protected connection from an encoded value.

How do I choose the right method in a Security+ question?

Choose the method from the required outcome: compare data with a hash, recover protected data with decryption, or change its representation with encoding. Read the business need before looking at the algorithms.

If the question adds authenticity, signatures or a keyed message authentication code may be needed. Ordinary hashing alone doesn’t supply them. Likewise, encryption alone doesn’t always detect changes; authenticated encryption protects confidentiality and checks integrity together.

For key choices, continue with symmetric and asymmetric encryption.

For data travelling between systems, trace where VPNs, proxies and firewalls sit as well as the cryptographic method.

If a scan reports weak cryptography, scanning, testing and risk assessment answer different questions about that finding.

In performance-based tasks, identify the required security property before selecting a control or changing a setting.

Best Exam Apps

Prepare with CompTIA Security+ Practice

Concept lessons, explained practice, a firewall exercise and a daily study route across the five SY0-701 domains.

See the app
Download on the App StoreGet it on Google Play