Identity, Authentication, and Access Management Questions

Designing and operating identity and access control systems. Covers authentication protocols and standards (OAuth, SAML, OIDC, MFA), authorization models (RBAC, ABAC), identity lifecycle and privilege management, IAM architecture and automation, and access control across cloud and on-premises environments. The 'who can do what' control plane, distinct from cryptographic key management.

EasyTechnical
60 practiced

Explain the structure of a JSON Web Token (JWT): header, payload (claims), and signature/encryption. Describe the difference between signed JWTs (JWS) and encrypted JWTs (JWE). When is confidentiality required (use JWE) versus only integrity/authenticity (JWS)? Describe risks of placing sensitive data in token claims and best practices for claim design.

HardSystem Design
36 practiced

Design a high-performance Attribute-Based Access Control (ABAC) policy evaluation engine capable of handling 1,000,000 authorization checks per second with complex policies and dynamic attributes. Include your choice of policy language, attribute retrieval and caching strategies, policy compilation or pre-evaluation techniques, consistency vs freshness trade-offs, horizontal scaling, and how you'd test correctness and performance under load.

MediumSystem Design
44 practiced

Design a system for issuing, rotating, and revoking API keys used by services and external partners. The system must support automated rotation without downtime, bind keys to service identities and scopes, provide audit trails, integrate with CI/CD and secret managers, and support emergency revocation. Describe issuance flows, rotation strategies (rolling, short-lived), migration for consumers, and how to deprecate long-lived keys in favor of ephemeral tokens.

MediumTechnical
33 practiced

Compare JWT (self-contained) tokens and opaque tokens. Explain verification differences, revocation strategies, performance characteristics, security tradeoffs, and when you might choose one format over the other for access tokens and refresh tokens.

EasyTechnical
65 practiced

In Node.js using Express, outline middleware that verifies a Bearer JWT access token signed with RS256 by using a JWKS endpoint. Provide the high-level pseudocode, list error cases to handle (expired, malformed, unknown kid), and explain how to cache JWKS keys safely to avoid performance problems.

Unlock Full Question Bank

Get access to all Identity, Authentication, and Access Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.