Applied Cryptography and Key Management Questions

Selecting and applying cryptographic primitives correctly: symmetric and asymmetric encryption, hashing, digital signatures, key derivation, secure random number generation, and public key infrastructure. Covers key lifecycle management, key exchange and distribution, choosing appropriate algorithms for a given constraint set including resource-constrained environments, and the forward-looking side of algorithm lifecycle: cryptographic agility and algorithm-migration strategy, forward secrecy, and the post-quantum cryptography transition and planning upgrades without breaking existing data or interoperability. The applied-crypto engineering layer, distinct from compliance-driven crypto standards.

EasyTechnical
51 practiced

Why can't you just hash a password with SHA-256 and call it done? Walk through what a key derivation function actually is (how it differs from a plain hash or a PRF) and compare PBKDF2, bcrypt, scrypt, and Argon2 as password-storage choices: the core mechanism each relies on (iteration count vs memory hardness), typical parameter knobs, and strengths/weaknesses. Then explain how the calculus changes when you're deriving a session key from an already-random shared secret instead of a low-entropy password, and where HKDF fits that case.

MediumTechnical
26 practiced

Describe practical techniques for protecting key material in the memory of a running system: zeroization, mlock/VirtualLock to prevent paging to disk, guard pages, dedicated secure-memory APIs, and hardware secure enclaves. What are the limitations of these techniques on modern operating systems and managed runtimes like the JVM or CPython?

EasyTechnical
33 practiced

Summarize NIST's post-quantum cryptography standardization effort: which algorithm families and specific algorithms has NIST selected for KEMs and signatures, and how should an organization use that activity when planning a migration? Explain why production deployments favor hybrid classical-plus-PQ patterns (parallel key encapsulation, dual signatures) rather than switching outright, and the main pitfalls to avoid when implementing a hybrid.

MediumTechnical
28 practiced

Design a migration strategy to move a user database from PBKDF2 to Argon2id without forcing a mass password reset. Cover the schema changes needed to version hashes, the authentication-flow change that detects an old hash and re-hashes on successful login, options for migrating accounts that never log in again, and the metrics you'd watch to confirm the migration is succeeding.

HardTechnical
31 practiced

Compare the security assurances of TPMs, dedicated HSMs, and cloud-provider KMS hardware-backed stores: tamper resistance, certification levels (FIPS/Common Criteria), remote-attestation strength, supply-chain concerns, and firmware-update posture. How do these differences actually drive key-lifecycle and policy decisions in a highly regulated environment?

Unlock Full Question Bank

Get access to all Applied Cryptography and Key Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.