Secure Coding and Application Security Questions

Writing and reviewing code that resists attack. Covers the OWASP Top Ten and common web vulnerabilities (XSS, SQL injection, CSRF), input validation, secure coding practices and security code review, static application security testing (SAST), API and HTTP security, database and frontend security, and mobile app security. The application-layer defense discipline for engineers building software.

HardTechnical
39 practiced

Compare JWT-based stateless authentication with stateful session stores in large microservice environments. Discuss the token-revocation challenges stateless tokens introduce, how each approach handles horizontal scaling, and when you would choose one over the other.

MediumTechnical
38 practiced

A JSON-based API echoes a user-supplied parameter into a JavaScript client response inside a single-page application. Describe how you would test for DOM-based XSS: what instrumentation you would use (browser devtools, a Burp extension, automated DOM-sink scanning), a safe proof-of-concept payload skeleton, and how you would triage and classify the finding.

MediumTechnical
41 practiced

A microservice accepts arbitrary URLs to fetch thumbnails and was abused to perform SSRF calls to internal metadata endpoints. Propose a layered mitigation plan covering input validation and URL canonicalization, an allowlist of permitted destinations, egress filtering and network segmentation, proxying requests through a vetted fetch service, and runtime detection for anomalous outbound requests.

EasyTechnical
46 practiced

Explain the concept of memory safety and the common memory-related vulnerabilities: buffer overflow, use-after-free, integer overflow, and format-string bugs. For each, give a concise example of the coding pattern that causes it and how modern languages or tooling help prevent it.

HardSystem Design
40 practiced

Design a safe sandbox to execute untrusted Python scripts uploaded by users (for example, user-provided data-preprocessing logic). Cover runtime isolation options, resource limits (CPU, memory, time), filesystem and network restrictions, and how you would prevent sandbox escapes.

Unlock Full Question Bank

Get access to all Secure Coding and Application Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.