Secure Coding and Application Security Questions

Writing and reviewing code that resists attack. Covers the OWASP Top Ten and common web vulnerabilities (XSS, SQL injection, CSRF), input validation, secure coding practices and security code review, static application security testing (SAST), API and HTTP security, database and frontend security, and mobile app security. The application-layer defense discipline for engineers building software.

MediumTechnical
36 practiced

In a modern single-page-application-plus-REST-API architecture, how would you implement CSRF defenses? Describe how SameSite cookie attributes, anti-CSRF tokens (double-submit cookie), and origin checks complement or conflict with JWTs carried in Authorization headers, and whether storing a token in localStorage changes the calculus. Recommend a default approach for a large organization, and explain why you would choose it over the alternatives.

MediumTechnical
37 practiced

You are given a Java servlet endpoint that returns order details:

java
protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws IOException {
    String orderId = req.getParameter("orderId");
    PreparedStatement ps = conn.prepareStatement("SELECT * FROM orders WHERE id = ?");
    ps.setString(1, orderId);
    ResultSet rs = ps.executeQuery();
    if (rs.next()) {
        resp.getWriter().println(rs.getString("details"));
    } else {
        resp.sendError(404);
    }
}

Identify the vulnerability, state which CWE(s) apply, and show the code change needed to add an authorization check that prevents this insecure direct object reference.

HardTechnical
39 practiced

A reporting dashboard uses dynamic SQL constructed by concatenating filters into a WHERE clause. Explain the SQL injection risk this creates and propose safe alternatives for a BI/reporting-tool integration (e.g. a Looker-, Power BI-, or Tableau-style query layer). Provide example code patterns for parameterized queries, allow-listing column/table identifiers, and safely escaping LIKE wildcards.

MediumTechnical
59 practiced

Implement a secure function get_user_by_name(conn, username) using parameterized queries suitable for psycopg2. The implementation must avoid SQL injection, correctly handle Unicode input, and return results as dictionaries. Outline how you would test this function against SQL injection attempts.

MediumTechnical
40 practiced

Implement a Node.js validation function validateProfile(payload) that verifies: (1) payload.email is a valid RFC-5322-ish email address, (2) payload.age is an integer between 0 and 120, and (3) payload.avatar is a well-formed URL from an allowed set of hosts. Return structured validation errors rather than throwing, and explain the security reasoning behind each check.

Unlock Full Question Bank

Get access to all 42 Secure Coding and Application Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.