Applied Cryptography and Key Management Questions

Selecting and applying cryptographic primitives correctly: symmetric and asymmetric encryption, hashing, digital signatures, key derivation, secure random number generation, and public key infrastructure. Covers key lifecycle management, key exchange and distribution, choosing appropriate algorithms for a given constraint set including resource-constrained environments, and the forward-looking side of algorithm lifecycle: cryptographic agility and algorithm-migration strategy, forward secrecy, and the post-quantum cryptography transition and planning upgrades without breaking existing data or interoperability. The applied-crypto engineering layer, distinct from compliance-driven crypto standards.

EasyTechnical
27 practiced

What is a Key Management Service, and what does the full key-management lifecycle look like for symmetric and asymmetric keys in an enterprise environment? For each stage (generation, provisioning, storage/usage, rotation, revocation, archival, secure destruction), name concrete controls and automation options you'd expect a KMS or HSM to provide, and the audit/logging you'd want at each stage. Compare cloud-managed KMS, HSM-backed KMS, and self-hosted key stores (like HashiCorp Vault) from an operational and decision-criteria standpoint: when would you reach for each?

EasyTechnical
51 practiced

Why can't you just hash a password with SHA-256 and call it done? Walk through what a key derivation function actually is (how it differs from a plain hash or a PRF) and compare PBKDF2, bcrypt, scrypt, and Argon2 as password-storage choices: the core mechanism each relies on (iteration count vs memory hardness), typical parameter knobs, and strengths/weaknesses. Then explain how the calculus changes when you're deriving a session key from an already-random shared secret instead of a low-entropy password, and where HKDF fits that case.

EasyTechnical
31 practiced

Describe the core components and trust model of an enterprise Public Key Infrastructure: root CA, intermediate CAs, issuing CAs, certificate profiles and validity periods, registration authorities, and the strategies (offline root, short-lived certs, cross-certification) used to limit blast radius if a CA is compromised. Then walk through what actually happens end to end for one certificate: how it's requested and issued (CSR, CA validation), how a client validates the resulting chain (chain verification, hostname checks), and how automated issuance (e.g. Let's Encrypt / ACME) changes that story at scale.

HardTechnical
27 practiced

Explain the cryptographic differences between RSA key exchange and ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) in TLS. Specifically, how does each impact perfect forward secrecy, and what are the consequences if the server's long-term private key is later compromised? What server configuration changes would you make to prioritize forward secrecy, and why?

EasyTechnical
50 practiced

Describe the purpose of a salt in password-based key derivation: what properties it needs (uniqueness, length, randomness), where it should be stored relative to the derived hash, and the operational risks of reusing or omitting it at scale. Then explain the difference between a salt and a pepper: how does adding a server-side secret pepper change the threat model for offline attacks, and what controls does protecting a pepper actually require?

Unlock Full Question Bank

Get access to all 8 Applied Cryptography and Key Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.