StudyToCert

All certifications / SSCP / Lessons

ISC2 SSCP Oct 2025 outline · Domain 5: Cryptography

Hashing, salting, HMAC and digital signatures

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

A cryptographic hash function takes input of any size and produces a fixed-size output called a digest or hash. It is one-way: you cannot feasibly recover the input from the digest. It is deterministic: the same input always yields the same digest. And a tiny change to the input produces a completely different output, which makes hashes ideal for detecting changes. A good hash must also be collision resistant, meaning it is infeasible to find two different inputs with the same digest. The SHA-2 family (such as SHA-256 and SHA-512) and SHA-3 are current choices. MD5 and SHA-1 have practical collision attacks and should not be used for security purposes, though you still see them used for non-security checksums.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SSCP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SSCP study plan