1.4 Explain the importance of using appropriate cryptographic solutions
Domain 1: General Security Concepts
Cryptography is the heaviest objective in Domain 1 and the one most likely to appear across other domains. Master the core contrasts: symmetric versus asymmetric encryption, hashing versus encryption, and encryption levels (full-disk, partition, file, volume, database, record). Know PKI mechanics — public and private keys, key escrow, certificate authorities, CSRs, OCSP, and certificate types including wildcard and self-signed. Newer SY0-701 additions get tested: blockchain, open public ledgers, salting, key stretching, digital signatures, and tools like TPM, HSM, KMS, and secure enclaves. Obfuscation methods (steganography, tokenization, data masking) are compared against real encryption. Exam questions favor purpose over math: which tool protects keys on a laptop (TPM), which process defeats rainbow tables (salting), which construct provides integrity plus authenticity (digital signature). You never compute anything; you match the mechanism to the security property it delivers.
What you must know
- Symmetric vs asymmetric
- PKI and certificates
- Hashing and salting
- TPM, HSM, KMS
- Digital signatures
- Tokenization vs masking
common pitfall · Candidates say encryption when the question asks for integrity — hashing and digital signatures prove data was not altered, while encryption only provides confidentiality.
Is objective 1.4 your weak spot?
The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.
Check my readiness — free