Secure Coding and Application Security Questions

Writing and reviewing code that resists attack. Covers the OWASP Top Ten and common web vulnerabilities (XSS, SQL injection, CSRF), input validation, secure coding practices and security code review, static application security testing (SAST), API and HTTP security, database and frontend security, and mobile app security. The application-layer defense discipline for engineers building software.

EasyTechnical
40 practiced

Explain the three types of Cross-Site Scripting (stored, reflected, and DOM-based): how each one arises in source code and executes at runtime, how they map to CWE-79, and the concrete mitigations you would apply for each (output encoding, safe templating, Content Security Policy, sanitization libraries).

HardTechnical
36 practiced

Propose a comprehensive mitigation strategy for insecure deserialization across Java, Python, and Node services. Cover code-level patterns (type whitelisting, safe serializers, schema validation), runtime protections (serialization filters, sandboxing, capability restrictions), how you would detect both in source code and at runtime, recommended libraries and formats, and a pragmatic, incremental migration plan for legacy services that currently rely on native serialization.

MediumTechnical
36 practiced

In a modern single-page-application-plus-REST-API architecture, how would you implement CSRF defenses? Describe how SameSite cookie attributes, anti-CSRF tokens (double-submit cookie), and origin checks complement or conflict with JWTs carried in Authorization headers, and whether storing a token in localStorage changes the calculus. Recommend a default approach for a large organization, and explain why you would choose it over the alternatives.

EasyTechnical
37 practiced

Define insecure deserialization, describe how it leads to remote code execution or a logic-bypass, and list the common language-specific risks (Java native serialization, Python pickle, PHP unserialize()). Explain where in an application deserialization typically happens (cookies, RPC calls, message queues), recommend secure design patterns and runtime mitigations, and note the detection signals you would look for in application logs and crash traces.

EasyTechnical
38 practiced

Describe device attestation services available for mobile platforms: Android SafetyNet and Play Integrity, and Apple DeviceCheck and App Attest. Explain what an attestation actually asserts about the device and app, how the server should validate an attestation response, and known limitations or attacks against attestation.

Unlock Full Question Bank

Get access to all Secure Coding and Application Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.