Applied Cryptography and Key Management Questions

Selecting and applying cryptographic primitives correctly: symmetric and asymmetric encryption, hashing, digital signatures, key derivation, secure random number generation, and public key infrastructure. Covers key lifecycle management, key exchange and distribution, choosing appropriate algorithms for a given constraint set including resource-constrained environments, and the forward-looking side of algorithm lifecycle: cryptographic agility and algorithm-migration strategy, forward secrecy, and the post-quantum cryptography transition and planning upgrades without breaking existing data or interoperability. The applied-crypto engineering layer, distinct from compliance-driven crypto standards.

EasyTechnical
34 practiced

Explain the 'quantum threat timeline' and its practical implications for long-term confidentiality. Describe the 'harvest-now, decrypt-later' threat model, give a reasonable range for when a large-scale quantum computer could threaten RSA/ECC, and explain how that timeline should influence which assets get prioritized for migration and what cryptoperiods you'd set.

MediumTechnical
33 practiced

A critical vulnerability affecting TLS handshakes (for example, in OpenSSL) is published, and you're responsible for a set of production services. Outline your immediate containment actions, how you'd prioritize patching, your test-and-rollout strategy (canaries, staged restarts), and any rekeying or certificate reissuance you'd need. What changes if the vulnerability is instead a side-channel in a widely-deployed post-quantum signature implementation that may leak private-key material: how would you measure exposure and plan the revocation/rotation for affected keys?

MediumTechnical
33 practiced

Define a secure backup, archival, and disaster-recovery plan for master keys stored across HSMs and cloud KMS. Specify RPO/RTO targets, storage protections (encryption of backups, key wrapping), geographic distribution, access controls for retrieval, key-splitting or escrow options, and how you'd test recovery safely without exposing the backup itself.

MediumTechnical
28 practiced

Design a migration strategy to move a user database from PBKDF2 to Argon2id without forcing a mass password reset. Cover the schema changes needed to version hashes, the authentication-flow change that detects an old hash and re-hashes on successful login, options for migrating accounts that never log in again, and the metrics you'd watch to confirm the migration is succeeding.

EasyTechnical
34 practiced

Design role-based access control and separation of duties for a corporate key-management system. Define at least four concrete roles (for example key-admin, operator, auditor, approver, backup-operator) and the minimum permissions each needs for key creation, use, rotation, archival, and destruction. What technical controls (in an HSM or a cloud KMS) actually enforce least privilege and approval workflows here, rather than just documenting them?

Unlock Full Question Bank

Get access to all Applied Cryptography and Key Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.