Crypto · TLS & PKI interview questions

72 Crypto · TLS & PKI questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is TLS?

Junior
  1. A.HTTP layered over TLS to provide encrypted, authenticated web communication
  2. B.Server Name Indication, a TLS extension letting a client specify the hostname so a server can present the right certificate
  3. C.signed list of certificates a CA has revoked before their expiry
  4. D.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL

Answer + AI explanation with Pro

2. Which term means: "Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL"?

Junior
  1. A.HTTPS
  2. B.TLS
  3. C.CAA record
  4. D.OCSP

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.TLS — DNS record specifying which CAs are authorized to issue certificates for a domain
  2. B.TLS — TLS where both client and server present and verify certificates for two-way authentication
  3. C.TLS — Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
  4. D.TLS — signed list of certificates a CA has revoked before their expiry

Answer + AI explanation with Pro

4. What is Certificate Authority (CA)?

Junior
  1. A.forcing peers to negotiate a weaker protocol or cipher than both actually support
  2. B.trusted entity that issues and signs digital certificates binding identities to public keys
  3. C.request containing a public key and identity sent to a CA to obtain a signed certificate
  4. D.latest TLS version with a faster 1-RTT handshake and removal of legacy insecure ciphers

Answer + AI explanation with Pro

5. Which term means: "trusted entity that issues and signs digital certificates binding identities to public keys"?

Junior
  1. A.Certificate Authority (CA)
  2. B.Certificate chain
  3. C.Self-signed certificate
  4. D.TLS 1.3

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.Certificate Authority (CA) — signed list of certificates a CA has revoked before their expiry
  2. B.Certificate Authority (CA) — trusted entity that issues and signs digital certificates binding identities to public keys
  3. C.Certificate Authority (CA) — TLS where both client and server present and verify certificates for two-way authentication
  4. D.Certificate Authority (CA) — request containing a public key and identity sent to a CA to obtain a signed certificate

Answer + AI explanation with Pro

7. What is X.509 certificate?

Junior
  1. A.public append-only logs of issued certificates so mis-issuance can be detected
  2. B.framework of CAs, certificates, and policies for managing public-key encryption and trust
  3. C.standard format for a public-key certificate containing identity, public key, and CA signature
  4. D.Online Certificate Status Protocol for checking in real time whether a certificate has been revoked

Answer + AI explanation with Pro

8. Which term means: "standard format for a public-key certificate containing identity, public key, and CA signature"?

Junior
  1. A.Cipher suite
  2. B.TLS
  3. C.Downgrade attack
  4. D.X.509 certificate

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.X.509 certificate — automated protocol (used by Let's Encrypt) for issuing and renewing certificates without manual steps
  2. B.X.509 certificate — certificate signed by its own key rather than a trusted CA, untrusted by default
  3. C.X.509 certificate — standard format for a public-key certificate containing identity, public key, and CA signature
  4. D.X.509 certificate — ordered path from a server's leaf certificate through intermediates up to a trusted root CA

Answer + AI explanation with Pro

10. What is Public Key Infrastructure (PKI)?

Junior
  1. A.forcing peers to negotiate a weaker protocol or cipher than both actually support
  2. B.ordered path from a server's leaf certificate through intermediates up to a trusted root CA
  3. C.standard format for a public-key certificate containing identity, public key, and CA signature
  4. D.framework of CAs, certificates, and policies for managing public-key encryption and trust

Answer + AI explanation with Pro

11. Which term means: "framework of CAs, certificates, and policies for managing public-key encryption and trust"?

Junior
  1. A.Public Key Infrastructure (PKI)
  2. B.X.509 certificate
  3. C.Certificate Signing Request (CSR)
  4. D.OCSP stapling

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Public Key Infrastructure (PKI) — Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
  2. B.Public Key Infrastructure (PKI) — framework of CAs, certificates, and policies for managing public-key encryption and trust
  3. C.Public Key Infrastructure (PKI) — certificate signed by its own key rather than a trusted CA, untrusted by default
  4. D.Public Key Infrastructure (PKI) — HTTP Strict Transport Security header forcing browsers to use HTTPS and refuse insecure connections

Answer + AI explanation with Pro

13. What is HTTPS?

Junior
  1. A.standard format for a public-key certificate containing identity, public key, and CA signature
  2. B.forcing peers to negotiate a weaker protocol or cipher than both actually support
  3. C.HTTP layered over TLS to provide encrypted, authenticated web communication
  4. D.DNS record specifying which CAs are authorized to issue certificates for a domain

Answer + AI explanation with Pro

14. Which term means: "HTTP layered over TLS to provide encrypted, authenticated web communication"?

Junior
  1. A.HTTPS
  2. B.OCSP
  3. C.Cipher suite
  4. D.TLS 1.3

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.HTTPS — Server Name Indication, a TLS extension letting a client specify the hostname so a server can present the right certificate
  2. B.HTTPS — HTTP layered over TLS to provide encrypted, authenticated web communication
  3. C.HTTPS — TLS where both client and server present and verify certificates for two-way authentication
  4. D.HTTPS — framework of CAs, certificates, and policies for managing public-key encryption and trust

Answer + AI explanation with Pro

16. What is TLS handshake?

Mid
  1. A.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
  2. B.negotiation where client and server agree on a cipher suite, authenticate, and establish session keys
  3. C.Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
  4. D.HTTP Strict Transport Security header forcing browsers to use HTTPS and refuse insecure connections

Answer + AI explanation with Pro

17. Which term means: "negotiation where client and server agree on a cipher suite, authenticate, and establish session keys"?

Mid
  1. A.Certificate Transparency
  2. B.Certificate Signing Request (CSR)
  3. C.TLS handshake
  4. D.Wildcard certificate

Answer + AI explanation with Pro

18. Which statement is correct?

Mid
  1. A.TLS handshake — public append-only logs of issued certificates so mis-issuance can be detected
  2. B.TLS handshake — signed list of certificates a CA has revoked before their expiry
  3. C.TLS handshake — negotiation where client and server agree on a cipher suite, authenticate, and establish session keys
  4. D.TLS handshake — latest TLS version with a faster 1-RTT handshake and removal of legacy insecure ciphers

Answer + AI explanation with Pro

19. What is Certificate chain?

Mid
  1. A.request containing a public key and identity sent to a CA to obtain a signed certificate
  2. B.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
  3. C.Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
  4. D.ordered path from a server's leaf certificate through intermediates up to a trusted root CA

Answer + AI explanation with Pro

20. Which term means: "ordered path from a server's leaf certificate through intermediates up to a trusted root CA"?

Mid
  1. A.Certificate chain
  2. B.X.509 certificate
  3. C.Certificate Authority (CA)
  4. D.Certificate Revocation List (CRL)

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Certificate chain — HTTP layered over TLS to provide encrypted, authenticated web communication
  2. B.Certificate chain — automated protocol (used by Let's Encrypt) for issuing and renewing certificates without manual steps
  3. C.Certificate chain — TLS where both client and server present and verify certificates for two-way authentication
  4. D.Certificate chain — ordered path from a server's leaf certificate through intermediates up to a trusted root CA

Answer + AI explanation with Pro

22. What is Cipher suite?

Mid
  1. A.TLS where both client and server present and verify certificates for two-way authentication
  2. B.HTTP Strict Transport Security header forcing browsers to use HTTPS and refuse insecure connections
  3. C.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
  4. D.named combination of key exchange, authentication, encryption, and MAC algorithms used in a TLS session

Answer + AI explanation with Pro

23. Which term means: "named combination of key exchange, authentication, encryption, and MAC algorithms used in a TLS session"?

Mid
  1. A.HSTS
  2. B.Certificate chain
  3. C.Cipher suite
  4. D.Certificate Revocation List (CRL)

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Cipher suite — trusted entity that issues and signs digital certificates binding identities to public keys
  2. B.Cipher suite — HTTP Strict Transport Security header forcing browsers to use HTTPS and refuse insecure connections
  3. C.Cipher suite — named combination of key exchange, authentication, encryption, and MAC algorithms used in a TLS session
  4. D.Cipher suite — negotiation where client and server agree on a cipher suite, authenticate, and establish session keys

Answer + AI explanation with Pro

25. What is Certificate Revocation List (CRL)?

Mid
  1. A.latest TLS version with a faster 1-RTT handshake and removal of legacy insecure ciphers
  2. B.certificate signed by its own key rather than a trusted CA, untrusted by default
  3. C.signed list of certificates a CA has revoked before their expiry
  4. D.request containing a public key and identity sent to a CA to obtain a signed certificate

Answer + AI explanation with Pro

26. Which term means: "signed list of certificates a CA has revoked before their expiry"?

Mid
  1. A.Certificate Revocation List (CRL)
  2. B.ACME protocol
  3. C.OCSP stapling
  4. D.Certificate Authority (CA)

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Certificate Revocation List (CRL) — signed list of certificates a CA has revoked before their expiry
  2. B.Certificate Revocation List (CRL) — request containing a public key and identity sent to a CA to obtain a signed certificate
  3. C.Certificate Revocation List (CRL) — HTTP layered over TLS to provide encrypted, authenticated web communication
  4. D.Certificate Revocation List (CRL) — Online Certificate Status Protocol for checking in real time whether a certificate has been revoked

Answer + AI explanation with Pro

28. What is OCSP?

Mid
  1. A.Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL
  2. B.Server Name Indication, a TLS extension letting a client specify the hostname so a server can present the right certificate
  3. C.Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
  4. D.certificate signed by its own key rather than a trusted CA, untrusted by default

Answer + AI explanation with Pro

29. Which term means: "Online Certificate Status Protocol for checking in real time whether a certificate has been revoked"?

Mid
  1. A.Downgrade attack
  2. B.X.509 certificate
  3. C.Self-signed certificate
  4. D.OCSP

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.OCSP — Online Certificate Status Protocol for checking in real time whether a certificate has been revoked
  2. B.OCSP — standard format for a public-key certificate containing identity, public key, and CA signature
  3. C.OCSP — named combination of key exchange, authentication, encryption, and MAC algorithms used in a TLS session
  4. D.OCSP — Transport Layer Security, the protocol that encrypts and authenticates data in transit, successor to SSL

Answer + AI explanation with Pro

Showing 30 of 72 Crypto · TLS & PKI questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Crypto · TLS & PKI question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers