Cryptography Fundamentals Questions

Core concepts and vocabulary of cryptography: confidentiality, integrity, authentication, and non-repudiation; the difference between symmetric and asymmetric primitives; and how standard algorithms, libraries, and protocols fit together. Covers threat models, common standards, and applying primitives and cryptographic libraries correctly to real-world security problems. The entry point for the cryptography track.

MediumTechnical
90 practiced

Walk through the hybrid (envelope) encryption pattern for protecting a large file or a message sent to multiple recipients: how the symmetric session key is generated, how it is wrapped with each recipient's public key, what integrity/authenticity protection you'd add, and how you'd support forward secrecy for recipients if the file might be re-shared later.

HardTechnical
67 practiced

Your organization still relies on SHA-1 in legacy components including certificate signatures and internal git repositories. Create a phased migration plan to stronger hashes (SHA-256 or better) that minimizes downtime, covers certificate replacement and repository migration, addresses interoperability with older clients, and verifies successful migration.

EasyTechnical
94 practiced

Compare Message Authentication Codes (like HMAC or CMAC) with digital signatures: when would you use each for authentication and integrity, and how do they differ in non-repudiation, key management (shared vs asymmetric key), and performance in an enterprise setting?

MediumTechnical
92 practiced

A microservice needs to encrypt small high-frequency messages with minimal latency. Evaluate trade-offs between using symmetric AEAD (AES-GCM), hybrid encryption per recipient, or public-key authenticated encryption. Consider throughput, key management complexity, bandwidth, and security properties (confidentiality, authentication). Recommend an approach and justify.

EasyTechnical
82 practiced

State recommended key length guidance for common algorithms: AES (symmetric), RSA (classical public-key), and elliptic curve algorithms (ECDSA/ECDH). Explain why key length matters and what operational considerations (performance, lifespan, algorithm migration) influence your choice of length.

Unlock Full Question Bank

Get access to all 41 Cryptography Fundamentals interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.