Secure Coding and Application Security Questions

Writing and reviewing code that resists attack. Covers the OWASP Top Ten and common web vulnerabilities (XSS, SQL injection, CSRF), input validation, secure coding practices and security code review, static application security testing (SAST), API and HTTP security, database and frontend security, and mobile app security. The application-layer defense discipline for engineers building software.

HardSystem Design
41 practiced

Design an approach to secure serverless (AWS Lambda) functions that process external input. As a penetration tester, list common serverless-specific vulnerabilities (e.g., excessive permissions, insecure environment variables, event-data injection), how you would test for them, and recommend secure deployment patterns and IAM best practices.

MediumTechnical
37 practiced

During authentication testing you find a password-reset token that is a short numeric value delivered via email. Describe how you would assess its security (entropy, predictability, rate limiting on guesses, expiry), what makes this weak, and the fix you would recommend.

HardSystem Design
37 practiced

Architect a secure API gateway for an enterprise that centralizes protection against injection, broken authentication/authorization, SSRF, and protocol abuse. Describe the components involved (authentication, authorization, WAF, mutual TLS, rate limiting, token introspection, egress controls, SSO protections), how the policies are enforced, how you would instrument detection, and trade-offs such as latency and operational complexity.

EasyTechnical
36 practiced

List and explain the most important cookie and session flags and properties to check when testing session management: HttpOnly, Secure, SameSite, session-ID entropy and rotation on login, and appropriate expiration. Explain what an attacker gains if each protection is missing.

EasyTechnical
34 practiced

Compare SAST, DAST, IAST, and SCA tools. For a web-application penetration-test engagement specifically, explain when you would use each type of tooling, what kinds of vulnerabilities each detects well, and where manual testing is still required regardless of tooling coverage.

Unlock Full Question Bank

Get access to all 49 Secure Coding and Application Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.