Identity, Authentication, and Access Management Questions

Designing and operating identity and access control systems. Covers authentication protocols and standards (OAuth, SAML, OIDC, MFA), authorization models (RBAC, ABAC), identity lifecycle and privilege management, IAM architecture and automation, and access control across cloud and on-premises environments. The 'who can do what' control plane, distinct from cryptographic key management.

HardTechnical
37 practiced

Propose a defense-in-depth architecture to prevent broken authentication logic. Include recommendations for centralizing authentication and authorization, canonicalizing inputs, using nonces/CSRF tokens, consistent error handling, secure defaults, and CI/testing gates to catch regressions.

MediumTechnical
33 practiced

Design roles and granular permissions for an HR application so that no single user can both create employees and approve payroll (separation of duties). Describe role templates, the atomic permissions set you would model, how to represent SoD constraints in the policy engine and UI, and how to detect and remediate SoD violations during access reviews.

MediumTechnical
44 practiced

Create a PowerShell solution (outline or code) to collect the local 'Administrators' group membership from every domain-joined computer in an OU, identify non-approved users, and produce a CSV report with computer name, account, SID, and whether the account is a domain or local account. Describe remoting and permission requirements.

HardTechnical
38 practiced

Design detection and alerting rules (for auditd + SIEM like Splunk/ELK) to detect suspicious user-administration activity: additions to /etc/sudoers or /etc/sudoers.d, changes to group 'sudo' membership, new SSH keys written to home directories, and creation of UID 0 users. Provide example auditd rules or file watches and high-level SIEM query patterns and thresholds to reduce false positives.

HardTechnical
39 practiced

Perform a threat modeling exercise for an enterprise IAM platform. Identify top attack vectors (token theft, account takeover, IdP compromise, provisioning abuse, privileged escalation, lateral movement) and propose concrete mitigations, detection strategies, and compensating controls for each vector.

Unlock Full Question Bank

Get access to all 22 Identity, Authentication, and Access Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.