Cryptography Fundamentals Questions

Core concepts and vocabulary of cryptography: confidentiality, integrity, authentication, and non-repudiation; the difference between symmetric and asymmetric primitives; and how standard algorithms, libraries, and protocols fit together. Covers threat models, common standards, and applying primitives and cryptographic libraries correctly to real-world security problems. The entry point for the cryptography track.

MediumTechnical
86 practiced

Compare an encrypt-then-MAC construction (e.g. AES-CBC + HMAC) against a dedicated AEAD cipher like AES-GCM for protecting an HTTP API payload. Cover performance, hardware acceleration, streaming support, IV/nonce requirements, and where each approach is more likely to be implemented incorrectly.

EasyTechnical
70 practiced

Give a high-level walkthrough of a TLS handshake: what happens at each step, which cryptographic primitives are used where (certificates, asymmetric key exchange, symmetric session keys, MAC/AEAD), and what properties TLS is actually trying to guarantee. What's one common way this can fail in practice?

EasyTechnical
98 practiced

Explain the roles of salting and key stretching in password-based key derivation and storage. Describe how salts should be generated and stored, why unique salts prevent precomputation/rainbow-table attacks, and how key stretching (iterative hashing, memory-hard functions) increases attacker work. Illustrate with concrete examples of attacks that salting and stretching mitigate and note any remaining risks that require additional controls.

HardTechnical
74 practiced

Your service currently stores passwords with a weak or legacy hashing scheme (say, unsalted SHA-1). Design the migration to a modern KDF like Argon2id: how you pick parameters for production versus constrained clients, how you support a rolling upgrade so users aren't forced to reset immediately, how you detect and re-hash the remaining weak legacy entries over time, and what you'd monitor to catch offline cracking attempts against the old hashes.

EasyTechnical
99 practiced

Explain the core security properties a cryptographic hash function must have (preimage resistance, second-preimage resistance, collision resistance), name a couple of common algorithms, and give one example each of where a hash is the right tool (integrity checks, content-addressing) and where it is not (storing passwords without salting and stretching).

Unlock Full Question Bank

Get access to all 17 Cryptography Fundamentals interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.