Secure Coding and Application Security Questions

Writing and reviewing code that resists attack. Covers the OWASP Top Ten and common web vulnerabilities (XSS, SQL injection, CSRF), input validation, secure coding practices and security code review, static application security testing (SAST), API and HTTP security, database and frontend security, and mobile app security. The application-layer defense discipline for engineers building software.

MediumTechnical
41 practiced

A microservice accepts arbitrary URLs to fetch thumbnails and was abused to perform SSRF calls to internal metadata endpoints. Propose a layered mitigation plan covering input validation and URL canonicalization, an allowlist of permitted destinations, egress filtering and network segmentation, proxying requests through a vetted fetch service, and runtime detection for anomalous outbound requests.

MediumTechnical
33 practiced

For a web application using cookie-based session tokens, describe the attack surface for CSRF, session fixation, and XSS. For each attack, describe at least two mitigation layers (application-level and infrastructure-level) you would implement, and explain the limitations or trade-offs of each control.

HardTechnical
33 practiced

Describe advanced WAF evasion techniques you might test during a penetration test (for example: mixed encoding, parameter pollution, polyglot payloads, chunked-request tricks). Pick one technique, explain how you would craft a proof of concept to demonstrate the bypass, and list the mitigations that should be applied at both the WAF and application levels.

HardTechnical
46 practiced

You must produce a concise risk assessment for a new serverless payment-processing function that retrieves secrets from a store, calls external payment gateways, and writes results to a database. Produce: (A) a short textual data-flow summary, (B) the top five concrete vulnerability risks ranked by severity, and (C) prioritized, code-level mitigations that fit a compliance-minded but agile team.

HardSystem Design
37 practiced

Architect a secure API gateway for an enterprise that centralizes protection against injection, broken authentication/authorization, SSRF, and protocol abuse. Describe the components involved (authentication, authorization, WAF, mutual TLS, rate limiting, token introspection, egress controls, SSO protections), how the policies are enforced, how you would instrument detection, and trade-offs such as latency and operational complexity.

Unlock Full Question Bank

Get access to all Secure Coding and Application Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.