Skip to content
Tech Interview Prep home
Technical interview guide

Encryption Fundamentals

Symmetric vs. asymmetric encryption, hashing, and how TLS combines them.

Read
30 min
Practice MCQs
25
Interview QA
25
Edition
v3
Editorial status
Reviewed

Scope: FIPS 197 update 1, NIST SP 800-57 Part 1 Rev. 5, RFC 8446, and official OWASP guidance accessed 2026-08-31..

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Compare encryption, hashing, MACs, and digital signatures.

QA-2

Why do production systems combine symmetric and asymmetric cryptography?

QA-3

Design a versioned AEAD record format for sensitive application fields.

QA-4

How do you guarantee nonce safety for AES-GCM at scale?

QA-5

Design password storage for a new authentication service.

QA-6

Migrate a legacy password-hash database without forcing every user offline.

QA-7

Design cryptographic protection for a system storing regulated personal data.

QA-8

Compare disk, database, and application-level encryption.

QA-9

Explain and design envelope encryption for a multi-service platform.

QA-10

Define the complete lifecycle for an application encryption key.

QA-11

Rotate encryption keys online without losing data or producing mixed-state ambiguity.

QA-12

How does Authenticated Encryption with Associated Data (AEAD) work, and why does combining independent encryption and MAC constructions often introduce vulnerabilities?

QA-13

How do KDFs and key separation improve a cryptographic design?

QA-14

Explain the TLS 1.3 handshake at an engineering level.

QA-15

How do hybrid post-quantum key exchange mechanisms such as X25519 combined with ML-KEM integrate into TLS 1.3, and what are their operational trade-offs?

QA-16

When should a service use mutual TLS, and what does it not solve?

QA-17

What is forward secrecy, and where are its limits?

QA-18

Design certificate renewal and emergency replacement without outage.

QA-19

How do you sign and verify release artifacts securely?

QA-20

Generate and validate security tokens such as password resets or API keys.

QA-21

What are the security and product tradeoffs of searching encrypted fields?

QA-22

What are the practical performance and compatibility implications of transitioning transport encryption to Post-Quantum Cryptography algorithms like ML-KEM and ML-DSA?

QA-23

Choose a key-isolation strategy for a multi-tenant SaaS product.

QA-24

Build cryptographic agility into a long-lived application protocol.

QA-25

Design end-to-end cryptographic controls for a multi-tenant financial API.