Identity, Authentication, and Access Management Questions

Designing and operating identity and access control systems. Covers authentication protocols and standards (OAuth, SAML, OIDC, MFA), authorization models (RBAC, ABAC), identity lifecycle and privilege management, IAM architecture and automation, and access control across cloud and on-premises environments. The 'who can do what' control plane, distinct from cryptographic key management.

HardTechnical
58 practiced

You're selecting cryptographic algorithms for signing and optionally encrypting access and refresh tokens. Evaluate symmetric (HMAC) vs asymmetric (RSA/ECDSA) signing, recommended algorithms and key sizes (e.g., RSASSA-PSS, ECDSA P-256), when to use JWE for token confidentiality, algorithm agility strategies, key rotation procedures, and performance implications for high-throughput services.

HardSystem Design
34 practiced

Design a high-availability and multi-region deployment for an IdP and directory service that must provide low latency (e.g., <5s for local auth) and survive a region failure. Discuss active-active vs active-passive replication, consistency tradeoffs, session state handling, DNS/routing strategies, and data residency constraints.

MediumTechnical
63 practiced

Describe the OAuth2 client credentials flow for machine-to-machine authentication. Explain how to store client secrets safely, options for rotating them, how to limit privileges for service accounts, and considerations for revocation and auditing of machine credentials in production.

EasyTechnical
38 practiced

Compare role-based access control (RBAC), attribute-based access control (ABAC), and policy-based access control (PBAC). Explain core concepts, provide one concrete example where each excels (enterprise admin vs dynamic resource policy), discuss advantages and disadvantages, and list considerations and pitfalls when migrating a large organization from RBAC to ABAC/PBAC.

HardTechnical
33 practiced

Evaluate managed identity provider (IdP) offerings versus building a custom IdP for a HIPAA-regulated enterprise handling sensitive health data. Create an evaluation and threat model comparing managed vs in-house solutions for data residency, auditability, key management, custom authentication flows, integration complexity, incident response obligations, and required contractual protections.

Unlock Full Question Bank

Get access to all Identity, Authentication, and Access Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.