Cryptography Fundamentals Questions

Core concepts and vocabulary of cryptography: confidentiality, integrity, authentication, and non-repudiation; the difference between symmetric and asymmetric primitives; and how standard algorithms, libraries, and protocols fit together. Covers threat models, common standards, and applying primitives and cryptographic libraries correctly to real-world security problems. The entry point for the cryptography track.

MediumTechnical
85 practiced

Compare block cipher modes of operation such as CBC and GCM. In a system that requires encryption for disks (at-rest logs) and for transport (TLS-like traffic), which mode(s) would you choose for each use case and why? Discuss IV/nonce requirements and integrity guarantees.

HardTechnical
74 practiced

Your service currently stores passwords with a weak or legacy hashing scheme (say, unsalted SHA-1). Design the migration to a modern KDF like Argon2id: how you pick parameters for production versus constrained clients, how you support a rolling upgrade so users aren't forced to reset immediately, how you detect and re-hash the remaining weak legacy entries over time, and what you'd monitor to catch offline cracking attempts against the old hashes.

EasyTechnical
70 practiced

Give a high-level walkthrough of a TLS handshake: what happens at each step, which cryptographic primitives are used where (certificates, asymmetric key exchange, symmetric session keys, MAC/AEAD), and what properties TLS is actually trying to guarantee. What's one common way this can fail in practice?

HardTechnical
95 practiced

Suppose a memory disclosure vulnerability similar to Heartbleed was discovered in an SSL/TLS library used by your fleet. Describe how you would detect whether exploitation occurred, immediate mitigations, patch rollout strategy, and post-incident tasks such as key and certificate rotation, forensic evidence collection, and customer notification.

MediumTechnical
96 practiced

Compare PBKDF2, bcrypt, scrypt, and Argon2 at a high level. For each describe its primary design goals, whether it is CPU-bound or memory-hard, how resistant it is to GPU/ASIC acceleration, and any known side-channel concerns. For a greenfield web service today, state which you would choose by default and justify that choice in terms of security and deployability.

Unlock Full Question Bank

Get access to all 26 Cryptography Fundamentals interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.