All questions
Showing of 46What is the difference between symmetric and asymmetric encryption?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
Symmetric encryption uses the same key for both encryption and decryption, while asymmetric encryption uses a pair of keys - a public key and a private key.
Symmetric Encryption:
- Same key for encrypt/decrypt
- Faster performance
- Key distribution challenge
- Examples: AES, DES, 3DES
Asymmetric Encryption:
- Public/private key pair
- Slower performance
- Solves key distribution problem
- Examples: RSA, ECC, DSA
Example scenario: If Alice wants to send a message to Bob using symmetric encryption, they both need to have the same secret key beforehand. With asymmetric encryption, Bob can share his public key openly, and Alice can encrypt messages that only Bob can decrypt with his private key.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What is AES and why is it widely used?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
AES (Advanced Encryption Standard) is a symmetric encryption algorithm adopted by the U.S. government and used worldwide. It replaced DES as the standard encryption algorithm.
Key features:
- Block cipher operating on 128-bit blocks
- Key sizes: 128, 192, or 256 bits
- Highly secure and efficient
- Resistant to known cryptographic attacks
- Fast implementation in both hardware and software
Why it's widely used:
- Strong security with no known practical attacks
- Excellent performance
- Standardized and well-tested
- Available in most cryptographic libraries
- Required for many compliance standards
AES is used in everything from HTTPS connections to file encryption and VPNs.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
Explain the concept of a digital signature and how it works.
What is the purpose of initialization vectors (IVs) in encryption?
What are the main advantages and disadvantages of symmetric vs asymmetric encryption?
What is the difference between HTTP and HTTPS?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
HTTP (HyperText Transfer Protocol) transmits data in plain text, making it vulnerable to interception and tampering. HTTPS (HTTP Secure) adds a security layer using TLS/SSL encryption.
Key differences:
- Security: HTTP is unencrypted; HTTPS encrypts all communication
- Port: HTTP uses port 80; HTTPS uses port 443
- Performance: HTTPS has slight overhead due to encryption/decryption
- Trust: HTTPS provides authentication, ensuring you're connecting to the intended server
- SEO: Search engines favor HTTPS websites
Example: When you log into your bank account, HTTPS ensures your credentials aren't visible to attackers on the network.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What does SSL stand for and how does it relate to TLS?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
SSL stands for Secure Sockets Layer. TLS (Transport Layer Security) is the successor to SSL. While people often use "SSL" colloquially, modern implementations actually use TLS.
Timeline:
- SSL 1.0: Never released (had security flaws)
- SSL 2.0: Released 1995, now deprecated
- SSL 3.0: Released 1996, now deprecated
- TLS 1.0: Released 1999 (based on SSL 3.0)
- TLS 1.1: Released 2006
- TLS 1.2: Released 2008
- TLS 1.3: Released 2018 (current standard)
When someone says "SSL certificate" today, they're actually referring to a certificate used with TLS.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What is a digital certificate and what information does it contain?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
A digital certificate is an electronic document that binds a public key to an identity (person, organization, or device). It's like a digital passport that proves authenticity.
Key information in a certificate:
- Subject: Who the certificate belongs to (domain name, organization)
- Public Key: Used for encryption and signature verification
- Issuer: The Certificate Authority that issued the certificate
- Validity Period: Start and expiration dates
- Serial Number: Unique identifier
- Signature: Digital signature from the issuing CA
- Extensions: Additional information (key usage, subject alternative names)
Example: A certificate for google.com proves that the public key belongs to Google, allowing secure communication.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What is a Certificate Authority (CA) and why is it important?
Explain the concept of public key cryptography.
What is SSL/TLS and what problem does it solve?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
SSL (Secure Sockets Layer) and TLS (Transport Layer Security) are cryptographic protocols that provide secure communication over computer networks. TLS is the successor to SSL, with TLS 1.0 being equivalent to SSL 3.1.
These protocols solve three main security problems:
- Confidentiality: Data is encrypted so only intended recipients can read it
- Integrity: Data cannot be modified in transit without detection
- Authentication: Verification of server (and optionally client) identity
TLS operates between the application layer and transport layer, securing protocols like HTTP (creating HTTPS), SMTP, FTP, and others.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What is PKI (Public Key Infrastructure) and what are its main components?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
PKI is a framework that manages digital keys and certificates for secure communication. It provides the infrastructure needed to create, manage, distribute, use, store, and revoke digital certificates.
Main Components:
- Certificate Authority (CA): Issues and manages certificates
- Registration Authority (RA): Verifies certificate requests before CA signs them
- Digital Certificates: Bind public keys to identities
- Certificate Repository: Stores and distributes certificates
- Certificate Revocation List (CRL): Lists revoked certificates
- Key Management: Handles key generation, storage, and lifecycle
PKI enables trust relationships between parties who have never met by establishing a chain of trust through trusted CAs.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What information is contained in an X.509 certificate?
Explain different block cipher modes of operation and their use cases.
What is Perfect Forward Secrecy (PFS) and why is it important?
Explain RSA encryption and its key components. What are its limitations?
What is key stretching and why is it used in password-based encryption?
Describe the Diffie-Hellman key exchange protocol and its security assumptions.
What is the difference between encryption and hashing? When would you use each?
Walk me through the TLS handshake process.
What is a certificate chain and how does certificate validation work?
What are cipher suites and what components do they include?
What is certificate pinning and when would you use it?
What is OCSP and how does it differ from CRL?
What are cipher suites and how do you interpret them?
How would you troubleshoot SSL/TLS connection issues?
How do you configure secure cipher suites and what are current best practices?
What is mutual TLS (mTLS) and when would you use it?
Explain the security implications of different padding schemes in RSA encryption.
Describe side-channel attacks against cryptographic implementations and their countermeasures.
Explain the concept of post-quantum cryptography and why it's becoming important.
Describe the challenges and best practices for key management in enterprise environments.
Compare TLS 1.2 and TLS 1.3. What are the key improvements?
What is SNI (Server Name Indication) and why is it necessary?
Explain Certificate Transparency and its benefits.
What is HSTS (HTTP Strict Transport Security) and how does it work?
What are some common TLS/SSL vulnerabilities and how are they mitigated?
Explain DANE (DNS-Based Authentication of Named Entities) and its advantages.
What are the security considerations when implementing TLS in a microservices architecture?
How would you troubleshoot a TLS certificate issue in production?
What is the role of HSMs (Hardware Security Modules) in PKI infrastructure?
What are the security differences between TLS 1.2 and TLS 1.3?
How do you implement SSL/TLS termination and what are the considerations?
How do you manage certificate lifecycle in an enterprise environment?
How do you handle SSL/TLS in containerized environments?
Describe the security implications of SSL/TLS session resumption.
This answer is part of Pro.
The full written answer, with the trade-offs and follow-ups an interviewer will probe.
No matches
Try a different filter or search term.
Cryptography & TLS cheatsheet
- Core Concepts01
- Types of Encryption02
- Hashing Algorithms03
- Security Protocols & Standards04
- Modes of Operation (Block Ciphers)05
- Key Management Best Practices06
- Common Attack Vectors07
- Interview Quick Tips08
- Advanced Topics09
- Quick Reference Card10
- Remember for Interviews11
- + 5 more inside
39 of 46 Cryptography & TLS answers are in Pro.
Full answers, code samples, and AI explanations that go simpler or deeper. Cancel anytime.
- Full answers + code
- AI explanations, simpler or deeper
- 1,000 AI credits / month
- Cancel anytime
Change topic
Pick a different technology or stack. Your current topic stays put until you choose a new one.
MEAN
MongoDB, Express, Angular, Node.jsMERN
MongoDB, Express, React, Node.jsDjango
Python Full-Stack DevelopmentRuby on Rails
Convention over ConfigurationServerless on AWS
Serverless Architecture on AWSInterviewers also test these - they're common to every stack, whichever one you picked above.
Flutter Mobile
Flutter Cross-Platform Mobile DevelopmentInterviewers also test these - they're common to every stack, whichever one you picked above.
Spring Boot
Enterprise Java Development.NET
Microsoft EcosystemVue
Vue.js, Vite, TypeScript, Tailwind, Node.jsGo Backend
Golang, gRPC, PostgreSQL, Redis, RabbitMQInterviewers also test these - they're common to every stack, whichever one you picked above.
FastAPI
Python, FastAPI, SQLAlchemy, PostgreSQLReact Native
React, TypeScript, Redux, FirebaseiOS Native
Swift, SwiftUI, UIKit, FirebaseAndroid Native
Java, Jetpack Compose, FirebaseDevOps / Platform
Docker, Kubernetes, Terraform, CI/CDInterviewers also test these - they're common to every stack, whichever one you picked above.
AI Engineer
LLMs, RAG, Agents, EvalsAI-Powered Developer
Claude Code, Copilot, Agentic WorkflowsCore SWE Interview Prep
Data structures, algorithms, OS, concurrency, networking, gitInterviewers also test these - they're common to every stack, whichever one you picked above.
Interviewers also test these - they're common to every stack, whichever one you picked above.