Cryptography & Secure Transport
The primitives every protocol stands on: hashing and integrity, symmetric and public-key encryption, key exchange, and the transport security (TLS/HTTPS) built from them.
Two strangers who have never met, on a wire anyone can read, need to agree on a secret — and then be sure they agreed it with each other and not with whoever was sitting in the middle. That sentence is the whole of this domain. Everything above it in the discipline assumes it has been solved: a login form is pointless if the password crosses the network in clear text, and a token proves nothing if anyone can mint one.
You solve it twice. First as primitives you build yourself — a hash used as a fingerprint, an HMAC that proves who wrote a message, a symmetric cipher whose mode visibly leaks the picture you encrypted when you choose the wrong one, and a Diffie-Hellman exchange that agrees a secret in the open and then fails, instructively, against someone standing in the middle. Then as the protocol the web actually runs: a certificate chain that closes exactly that gap, a TLS 1.3 handshake that turns out to be your Diffie-Hellman with the server's share signed, and the practical business of terminating HTTPS without undoing it. The domain ends with a capstone that assembles the parts into one working secure channel, so the primitives stop being separate toys.