Cryptography Fundamentals Questions

Core concepts and vocabulary of cryptography: confidentiality, integrity, authentication, and non-repudiation; the difference between symmetric and asymmetric primitives; and how standard algorithms, libraries, and protocols fit together. Covers threat models, common standards, and applying primitives and cryptographic libraries correctly to real-world security problems. The entry point for the cryptography track.

EasyTechnical
95 practiced

Describe Public Key Infrastructure (PKI) fundamentals: what a certificate is, what a Certificate Authority (CA) does, certificate chains and trust anchors, and a typical use of certificates in TLS. Keep the explanation high-level but include how trust is established and how certificate expiration affects secure channels.

EasyTechnical
74 practiced

Explain the fundamental differences between symmetric and asymmetric encryption. Name real algorithms in each category, describe typical enterprise use cases for each (data at rest, key exchange, code signing, TLS), and give one concrete advantage and one limitation of each approach.

EasyTechnical
99 practiced

Explain the core security properties a cryptographic hash function must have (preimage resistance, second-preimage resistance, collision resistance), name a couple of common algorithms, and give one example each of where a hash is the right tool (integrity checks, content-addressing) and where it is not (storing passwords without salting and stretching).

HardTechnical
71 practiced

Explain forward secrecy (and perfect forward secrecy): what does it protect against, and what doesn't it protect against (e.g. server long-term key compromise vs a single session key's exposure)? Describe how ephemeral Diffie-Hellman (ECDHE) achieves it in TLS, and what a server operator must configure correctly for it to actually apply.

EasyTechnical
98 practiced

Explain the roles of salting and key stretching in password-based key derivation and storage. Describe how salts should be generated and stored, why unique salts prevent precomputation/rainbow-table attacks, and how key stretching (iterative hashing, memory-hard functions) increases attacker work. Illustrate with concrete examples of attacks that salting and stretching mitigate and note any remaining risks that require additional controls.

Unlock Full Question Bank

Get access to all 11 Cryptography Fundamentals interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.