Skip to content
Tech Interview Prep home
Technical interview guide

Embedded Security

How a device establishes that its firmware hasn't been tampered with, and the physical-access attack classes that don't exist in typical server-side security.

Read
65 min
Practice MCQs
25
Interview QA
25
Edition
v3
Editorial status
Reviewed

Scope: PSA Crypto 1.5, Storage 1.0, Attestation 2.0; current TF-M and MCUboot; NIST IR 8259A/SP 800-193; OWASP ISVS 1.0 reviewed 2026-09-04.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Design and validate embedded security for threat model.

QA-2

Design and validate embedded security for lifecycle states.

QA-3

Design and validate embedded security for root of trust.

QA-4

Design and validate embedded security for authenticated boot.

QA-5

Design and validate embedded security for rollback protection.

QA-6

Design and validate embedded security for device identity.

QA-7

Design and validate embedded security for key storage.

QA-8

Design and validate embedded security for entropy.

QA-9

Design and validate embedded security for crypto API.

QA-10

Design and validate embedded security for nonce discipline.

QA-11

How do Arm TrustZone and Memory Protection Units (MPUs) enforce least privilege across security domains and RTOS task boundaries on Cortex-M?

QA-12

How do hardware and firmware countermeasures protect microcontrollers and secure enclaves against side-channel analysis (DPA/CPA) and fault injection attacks (clock and voltage glitching)?

QA-13

How do you prevent memory corruption vulnerabilities like buffer overflows and integer wraps when parsing variable-length payloads over low-level buses such as CAN, UART, or USB?

QA-14

Design and validate embedded security for input parsing.

QA-15

Design and validate embedded security for command authorization.

QA-16

Design and validate embedded security for replay.

QA-17

Design and validate embedded security for communications.

QA-18

Design and validate embedded security for debug interfaces.

QA-19

Design and validate embedded security for physical and fault attacks.

QA-20

Design and validate embedded security for side channels.

QA-21

Design and validate embedded security for secure updates.

QA-22

Design and validate embedded security for attestation.

QA-23

Design and validate embedded security for security telemetry.

QA-24

Design and validate embedded security for vulnerability lifecycle.

QA-25

Design and validate embedded security for lifecycle evidence.