Cryptography Fundamentals Questions

Core concepts and vocabulary of cryptography: confidentiality, integrity, authentication, and non-repudiation; the difference between symmetric and asymmetric primitives; and how standard algorithms, libraries, and protocols fit together. Covers threat models, common standards, and applying primitives and cryptographic libraries correctly to real-world security problems. The entry point for the cryptography track.

EasyTechnical
70 practiced

Give a high-level walkthrough of a TLS handshake: what happens at each step, which cryptographic primitives are used where (certificates, asymmetric key exchange, symmetric session keys, MAC/AEAD), and what properties TLS is actually trying to guarantee. What's one common way this can fail in practice?

EasyTechnical
70 practiced

Compare AES and DES/3DES: key and block sizes, why DES is considered insecure today, and what you'd need to consider when migrating a system that still has legacy DES-encrypted data.

EasyTechnical
87 practiced

Define initialization vector (IV) and nonce as used in block/stream cipher modes. What properties must each satisfy (randomness vs uniqueness), and what happens in practice if a nonce is reused with a mode like GCM?

EasyTechnical
70 practiced

Describe sources of randomness and entropy relevant to secure key generation in production systems. Compare hardware TRNGs, OS-provided CSPRNGs such as getrandom or /dev/urandom, and pitfalls of using non-cryptographic PRNGs or predictable seeding.

EasyTechnical
94 practiced

Compare Message Authentication Codes (like HMAC or CMAC) with digital signatures: when would you use each for authentication and integrity, and how do they differ in non-repudiation, key management (shared vs asymmetric key), and performance in an enterprise setting?

Unlock Full Question Bank

Get access to all 17 Cryptography Fundamentals interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.