Identity, Authentication, and Access Management Questions

Designing and operating identity and access control systems. Covers authentication protocols and standards (OAuth, SAML, OIDC, MFA), authorization models (RBAC, ABAC), identity lifecycle and privilege management, IAM architecture and automation, and access control across cloud and on-premises environments. The 'who can do what' control plane, distinct from cryptographic key management.

HardTechnical
36 practiced

Design a secure break-glass process for emergency privileged access that minimizes risk of abuse. Include required approvals, ephemeral credential issuance, session brokering/recording, forced post-usage attestation, cryptographic one-time tokens, and integration with SSO and PAM while maintaining forensic-grade audit trails.

EasyTechnical
57 practiced

Compare common Multi-Factor Authentication (MFA) approaches : TOTP (time-based OTP), SMS OTP, push-based approval, and hardware-backed/U2F/WebAuthn tokens : in terms of security, usability, deployability, and attack surface. For each method, list typical threats (e.g., SIM swapping, phishing, device theft) and describe when you would choose or avoid that method for a user-facing application.

HardSystem Design
34 practiced

Design an entitlement management and just-in-time (JIT) access service for enterprise customers: include request and approval flows, risk-based gating, issuing time-bound role grants, automated revocation, integration with HR and SSO, audit trail for every grant, and controls to prevent abuse (multi-approver for high-risk roles, automated SoD checks).

MediumTechnical
44 practiced

You must onboard external partners with SAML or OIDC federation. Draft a federation onboarding checklist covering metadata exchange, certificate validation, required attributes, scopes/claims, test cases, operational contacts, and trust lifecycle management including periodic validation and revocation procedures.

HardTechnical
58 practiced

A customer reports that after onboarding an external IdP, several users were mapped to elevated roles and accessed sensitive resources. Draft a post-incident analysis: identify likely root causes in federation/attribute-mapping processes, immediate containment and remediation steps, long-term fixes (validation, schema contracts, automated tests) and monitoring changes to prevent recurrence.

Unlock Full Question Bank

Get access to all Identity, Authentication, and Access Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.