Applied Cryptography and Key Management Questions
Selecting and applying cryptographic primitives correctly: symmetric and asymmetric encryption, hashing, digital signatures, key derivation, secure random number generation, and public key infrastructure. Covers key lifecycle management, key exchange and distribution, choosing appropriate algorithms for a given constraint set including resource-constrained environments, and the forward-looking side of algorithm lifecycle: cryptographic agility and algorithm-migration strategy, forward secrecy, and the post-quantum cryptography transition and planning upgrades without breaking existing data or interoperability. The applied-crypto engineering layer, distinct from compliance-driven crypto standards.
Design and operationalize a hardened private Certificate Authority for internet-facing services that includes Certificate Transparency (CT) logging (or internal CT), OCSP stapling, short-lived certificates, and automated renewal. Address scaling OCSP responders, CT integration for a private CA, and incident response if a CA key compromise occurs.
A vault's master key is suspected to be extracted. Draft an incident response plan covering containment (freeze usage), forensic verification, immediate business decisions, re-keying strategy for all encrypted data, cross-team responsibilities, regulatory/legal notifications, and estimated resource and timeline needs to remediate.
Design a hybrid cryptographic key management architecture that supports on-prem HSMs and multiple cloud KMS providers. Include a key hierarchy, unified access control and audit, key migration tools between providers, and operational considerations for multi-region redundancy. Assume enterprise scale: 10k keys and peak 1k encrypt/decrypt TPS.
Tell me about a time you planned and executed a production key rotation. Use the STAR method: describe the Situation, Task, Actions you took (including automation, testing and rollback), the Result, and one improvement you would add now. If you haven't performed one, describe a detailed plan you would execute.
Build a threat model for the compromise of an encryption key protecting customer PII at rest. Identify likely attack vectors, the business and regulatory impacts, detection signals you would instrument, containment and recovery actions, and design changes to reduce the blast radius.
Unlock Full Question Bank
Get access to all 33 Applied Cryptography and Key Management interview questions and detailed answers.
Sign in to ContinueJoin thousands of developers preparing for their dream job.