Cryptography Fundamentals Questions

Core concepts and vocabulary of cryptography: confidentiality, integrity, authentication, and non-repudiation; the difference between symmetric and asymmetric primitives; and how standard algorithms, libraries, and protocols fit together. Covers threat models, common standards, and applying primitives and cryptographic libraries correctly to real-world security problems. The entry point for the cryptography track.

EasyTechnical
70 practiced

Compare AES and DES/3DES: key and block sizes, why DES is considered insecure today, and what you'd need to consider when migrating a system that still has legacy DES-encrypted data.

MediumTechnical
91 practiced

Describe how you would perform a cryptographic library audit to find misuse (e.g., incorrect mode selection, improper padding, insecure defaults). What static and dynamic analysis tools or test vectors would you use, and how would you prioritize remediation across findings that vary in exploitability?

HardTechnical
80 practiced

Discuss common side-channel attacks (timing attacks, cache attacks, power analysis) relevant to cryptographic operations in cloud environments. For each, describe detection techniques, mitigation strategies for deployed libraries (constant-time implementations, blinding, hardware isolation), and pragmatically how you'd prioritize fixes in production.

MediumTechnical
72 practiced

Explain the padding oracle attack against CBC-mode encryption. Describe how an attacker can use padding error responses to decrypt ciphertext bytes and provide practical mitigations you would apply in a web service that handles encrypted cookies.

MediumTechnical
89 practiced

Explain the differences between collision resistance, preimage resistance, and second-preimage resistance in hash functions. Provide practical attack complexity estimates for MD5, SHA-1, and SHA-256, and state at what point you would mandate deprecation of a hashing algorithm within an organization.

That is every published Cryptography Fundamentals question for Penetration Tester so far. Browse the other topics in this category, or practice this one interactively.