Assembly and Low-Level Language Fundamentals Questions

Programming and debugging at the instruction level. Covers reading and writing assembly for x86-64 and ARM (A32, Thumb, AArch64), including small hand-written routines, vector (SIMD) code and exclusive load/store atomics, registers, the stack and frame layout, prologues and epilogues, calling conventions and ABIs (System V, Microsoft x64, AAPCS), variadic calls, inline assembly and its constraints and clobbers, Cortex-M exception entry and context-switch code written in assembly, and how compilers translate and optimize source into machine code (optimization flags, inlining, tail calls, LTO, aliasing, strength reduction, virtual dispatch, memcpy lowering, stack spills). Also covers object files and linking as they affect generated code (ELF, PE/COFF and Mach-O, relocations, GOT and PLT, position-independent code, static linking, stack unwinding), the compiler backend ideas behind it (SSA, register allocation, instruction selection, peephole passes) and emitting machine code from a minimal JIT. On the debugging side: reading disassembly, using gdb and lldb for registers, frames, breakpoints and watchpoints, analyzing core dumps and stripped binaries with addr2line and build IDs, and diagnosing crashes from instruction-level state such as corrupted returns, stack smashing, ABI mismatches and optimizer-induced bugs. Debugging method in general, hardware probe tooling, malware analysis and exploit-mitigation design are covered elsewhere.

HardTechnical
61 practiced

In a hardened binary, how would you determine whether a crash is caused by stack smashing, heap corruption, use-after-free, or a corrupted return address using only the assembly view, register contents, memory layout, and debugger evidence? Describe the distinctions you would look for in each case.

EasyTechnical
60 practiced

What is the practical difference between a software breakpoint and a hardware watchpoint in GDB or LLDB, and when would you prefer one over the other while investigating a security issue?

MediumTechnical
57 practiced

A stack buffer overflow is suspected in a service, but the crash is intermittent. How would you use the debugger to catch the exact instruction that corrupts the stack, and how would you tell whether the overwrite happened before or after the function's return address was last used?

MediumTechnical
69 practiced

How does a call to a shared-library function such as printf actually get resolved at runtime on x86-64 Linux? Walk through what the dynamic linker does, what the call site looks like, and how lazy binding differs from immediate binding.

MediumTechnical
77 practiced

How does a variadic C function such as printf find its extra arguments on x86-64 System V when some arrive in registers and some on the stack, and why does the caller set up an extra register before the call?

Unlock Full Question Bank

Get access to all 18 Assembly and Low-Level Language Fundamentals interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.