[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fsecurity-cryptography-basics":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","security-cryptography-basics","Security Cryptography Basics","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,90,93,96,99,102,105,108,111,114,117,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":82,"name":83,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":85,"name":86,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":88,"name":89,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":91,"name":92,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":94,"name":95,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":97,"name":98,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":100,"name":101,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":103,"name":104,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":106,"name":107,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":109,"name":110,"count":11},"security-authn-authz","Security Authn Authz",{"key":112,"name":113,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":115,"name":116,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":8,"name":9,"count":11},{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":157,"explanation":165},"019f686c-5967-738a-b53b-436c0f8f6358",1,"What is the core difference between symmetric and asymmetric encryption?",[153,156,159,162],{"key":154,"text":155},"a","Symmetric encryption can only encrypt text, asymmetric can encrypt any binary data",{"key":157,"text":158},"b","Symmetric uses the same key both ways; asymmetric uses a related key pair",{"key":160,"text":161},"c","Symmetric encryption is always weaker and should never be used in production",{"key":163,"text":164},"d","Asymmetric encryption does not require any key at all","Symmetric algorithms encrypt and decrypt with the same shared secret key. Asymmetric algorithms use a key pair — a public key for one operation and a mathematically related private key for the other — so no shared secret has to travel between parties.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":154,"explanation":178},"019f686c-5967-7cef-bf5d-9563d3157f02","What does it mean for a cryptographic hash function to be 'one-way'?",[170,172,174,176],{"key":154,"text":171},"Recovering the input from a hash output is computationally infeasible",{"key":157,"text":173},"The function can only be run once per input value",{"key":160,"text":175},"It only accepts input in one direction, such as left-to-right byte order",{"key":163,"text":177},"The output can be decrypted back to the input using the same function","One-wayness (preimage resistance) means that given a hash output, finding an input that produces it should be computationally infeasible. Hashing has no inverse\u002Fdecrypt operation, unlike encryption.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":160,"explanation":192},"019f686c-5968-7562-af33-afc1f2ca7c78",2,"Why is it a mistake to describe password hashing as 'encrypting' the password?",[184,186,188,190],{"key":154,"text":185},"Because hashing is always slower than encryption, so the terms aren't interchangeable performance-wise",{"key":157,"text":187},"Because hash functions require a public\u002Fprivate key pair while encryption does not",{"key":160,"text":189},"Because hashing is one-way with no decrypt step, while encryption is meant to be reversed with a key",{"key":163,"text":191},"Because encryption produces fixed-length output while hashing does not","Encryption is designed to be reversible: someone holding the correct key can decrypt ciphertext back to plaintext. Hashing has no decrypt counterpart by design, so calling it 'encrypting a password' wrongly suggests a reversal path that shouldn't exist for stored password hashes.",{"id":194,"topic":9,"difficulty":150,"body":195,"options":196,"correct_key":163,"explanation":205},"019f686c-5968-7ee2-a38f-d358193c60ce","Encrypting a large multi-gigabyte file directly with an asymmetric algorithm is far slower than using a symmetric algorithm for the same data. Why is asymmetric encryption still used at all in secure communication then?",[197,199,201,203],{"key":154,"text":198},"It isn't — asymmetric encryption is never actually used for real data protection",{"key":157,"text":200},"Asymmetric algorithms become faster than symmetric ones once the data exceeds a few hundred megabytes",{"key":160,"text":202},"Symmetric algorithms cannot handle binary file formats, only text",{"key":163,"text":204},"Asymmetric encryption exchanges a symmetric session key, which then encrypts the bulk data","Asymmetric operations are computationally expensive relative to symmetric ones, so protocols typically use asymmetric encryption only for a small piece of data — exchanging or wrapping a symmetric session key — then switch to fast symmetric encryption for the actual bulk data. This hybrid approach gets the key-distribution benefit of asymmetric crypto without paying its cost on large payloads.",{"id":207,"topic":9,"difficulty":181,"body":208,"options":209,"correct_key":154,"explanation":218},"019f686c-5969-7a31-8fbd-680f7640a8f5","Two users pick the identical password. Without salting, their stored password hashes would be identical, making them vulnerable to a precomputed lookup-table attack. What does adding a unique salt per user actually change?",[210,212,214,216],{"key":154,"text":211},"Identical passwords still hash differently per user, since salt is mixed in first",{"key":157,"text":213},"The salt encrypts the resulting hash so it can't be reversed at all",{"key":160,"text":215},"The salt replaces the password entirely, so the original password is never hashed",{"key":163,"text":217},"The salt makes the hash function reversible for authorized verification only","A per-user salt is combined with the password before hashing, so identical passwords produce different hash outputs across users. This defeats precomputed lookup tables built against unsalted hashes, since an attacker would need a separate table per salt value.",{"id":220,"topic":9,"difficulty":150,"body":221,"options":222,"correct_key":160,"explanation":231},"019f686c-596a-7440-a426-a658d275aa97","How does a 'pepper' differ from a 'salt' in password hashing?",[223,225,227,229],{"key":154,"text":224},"A pepper is stored alongside each password hash in the same database row, exactly like a salt",{"key":157,"text":226},"A pepper is unique per user, while a salt is shared across the whole system",{"key":160,"text":228},"A pepper is a separate secret; a salt is stored with the hash and isn't secret",{"key":163,"text":230},"A pepper replaces hashing entirely, using encryption instead","A salt is stored next to the hash and isn't meant to be secret — its job is uniqueness, not confidentiality. A pepper is an additional secret value, typically shared across the system and stored separately (e.g., in application configuration or a secrets manager), so that a database-only breach doesn't expose it.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]