Identity, Authentication, and Access Management Questions

Designing and operating identity and access control systems. Covers authentication protocols and standards (OAuth, SAML, OIDC, MFA), authorization models (RBAC, ABAC), identity lifecycle and privilege management, IAM architecture and automation, and access control across cloud and on-premises environments. The 'who can do what' control plane, distinct from cryptographic key management.

HardSystem Design
44 practiced

Design a continuous or adaptive authorization system that adjusts session trust in real time using signals such as device posture, IP reputation, behavioral anomalies, and recent authentication events. Explain how to represent and propagate trust level to microservices, how services should enforce it, and storage/caching strategies to keep decisions timely while auditable.

HardSystem Design
59 practiced

Design a Continuous Access Evaluation (CAE) system that enables near-immediate revocation of access when credentials are compromised or roles change. Describe how change events are detected, how they are securely propagated to enforcement points (API gateways, microservices, mobile clients), options for push vs pull invalidation, securing the propagation channel, and methods to minimize latency while scaling to tens of thousands of active sessions.

EasyTechnical
44 practiced

List TLS/HTTPS best practices to protect authentication credentials and tokens in transit for API services. Include minimum protocol versions, cipher suite recommendations, HSTS, certificate lifecycle management, and when mutual TLS is appropriate for stronger client authentication.

EasyTechnical
35 practiced

Explain Cross-Site Request Forgery (CSRF): how it works, typical attack chains, and at least four mitigation strategies for web applications. Include differences in mitigation when auth state is stored in cookies versus when Authorization headers are used.

EasyTechnical
44 practiced

Compare OAuth 2.0, OpenID Connect (OIDC), and SAML for solving authentication and authorization problems. For each protocol explain primary use cases (e.g., web SSO, mobile apps, enterprise federation), how authentication statements are conveyed, and typical deployment considerations (mobile vs enterprise SSO). Provide criteria you would use to choose one protocol over the others.

Unlock Full Question Bank

Get access to all Identity, Authentication, and Access Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.