Cryptography Fundamentals Questions

Core concepts and vocabulary of cryptography: confidentiality, integrity, authentication, and non-repudiation; the difference between symmetric and asymmetric primitives; and how standard algorithms, libraries, and protocols fit together. Covers threat models, common standards, and applying primitives and cryptographic libraries correctly to real-world security problems. The entry point for the cryptography track.

EasyTechnical
99 practiced

Explain the core security properties a cryptographic hash function must have (preimage resistance, second-preimage resistance, collision resistance), name a couple of common algorithms, and give one example each of where a hash is the right tool (integrity checks, content-addressing) and where it is not (storing passwords without salting and stretching).

EasyTechnical
94 practiced

Compare Message Authentication Codes (like HMAC or CMAC) with digital signatures: when would you use each for authentication and integrity, and how do they differ in non-repudiation, key management (shared vs asymmetric key), and performance in an enterprise setting?

EasyTechnical
95 practiced

Describe Public Key Infrastructure (PKI) fundamentals: what a certificate is, what a Certificate Authority (CA) does, certificate chains and trust anchors, and a typical use of certificates in TLS. Keep the explanation high-level but include how trust is established and how certificate expiration affects secure channels.

EasyTechnical
98 practiced

Explain the roles of salting and key stretching in password-based key derivation and storage. Describe how salts should be generated and stored, why unique salts prevent precomputation/rainbow-table attacks, and how key stretching (iterative hashing, memory-hard functions) increases attacker work. Illustrate with concrete examples of attacks that salting and stretching mitigate and note any remaining risks that require additional controls.

MediumTechnical
97 practiced

Describe elliptic curve cryptography (ECC) conceptually and explain why modern systems favor it over RSA for equivalent security: key sizes, computational cost, bandwidth, and typical use cases (signatures, key exchange). Name a couple of widely-used curves and any trade-offs worth flagging.

Unlock Full Question Bank

Get access to all 17 Cryptography Fundamentals interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.