All questions
Showing of 70What is the difference between Authentication and Authorization?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
Authentication is the process of verifying who a user is, while authorization determines what that authenticated user is allowed to do.
- Authentication answers "Who are you?" - It's about identity verification
- Authorization answers "What can you do?" - It's about permissions and access control
Example:
When you log into your email account: - Authentication: Entering your username/password proves you are the account owner
- Authorization: The system then determines if you can read emails, send emails, access admin settings, etc.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What are the main types of authentication factors?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
Authentication factors are categorized into three main types:
- Something you know (Knowledge factors)
- Passwords, PINs, security questions
- Something you have (Possession factors)
- Smartphones, hardware tokens, smart cards
- Something you are (Inherence factors)
- Biometrics: fingerprints, facial recognition, retina scans
Multi-Factor Authentication (MFA) combines two or more of these factors for enhanced security.
- Biometrics: fingerprints, facial recognition, retina scans
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What is session management and why is it important?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
Session management is the process of securely handling user sessions from login to logout. It maintains the user's authenticated state across multiple requests without requiring re-authentication for each action.
Key components:
- Session creation: Generated after successful authentication
- Session storage: Server-side storage of session data
- Session validation: Checking session validity on each request
- Session termination: Proper cleanup on logout or timeout
Importance: - Provides seamless user experience
- Maintains security state
- Prevents unauthorized access
- Enables proper audit trails
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What is the principle of least privilege?
What is Multi-Factor Authentication (MFA) and when should it be used?
Explain the different authentication factors and provide examples of each.
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
Authentication factors are categorized into three types:
- Something you know (Knowledge factors):
- Passwords, PINs, security questions
- Passphrases, secret keys
- Something you have (Possession factors):
- Smartphones with authenticator apps
- Hardware tokens, smart cards
- SMS tokens, email confirmations
- Something you are (Inherence factors):
- Fingerprints, facial recognition
- Retina scans, voice patterns
- Behavioral biometrics (typing patterns)
Multi-Factor Authentication (MFA) combines two or more of these factors to enhance security. For example, using a password (knowledge) + SMS code (possession) provides stronger security than password alone.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What are the three parts of a JWT token? Explain each part.
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
Header:
{
"alg": "HS256",
"typ": "JWT"
}
Contains metadata about the token, including the signing algorithm and token type.
Payload:
{
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022,
"exp": 1516242622
}
Contains claims - statements about an entity (typically the user) and additional data. Claims can be registered, public, or private.
Signature:
HMACSHA256(
base64UrlEncode(header) + "." +
base64UrlEncode(payload),
secret
)
Used to verify that the sender of the JWT is who it says it is and to ensure that the message wasn't changed along the way.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What are the three main categories of authentication factors?
Answer it yourself first - out loud, or typed below.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Last attempt -
The three main categories of authentication factors are:
Something You Know (Knowledge Factor)
- Passwords, PINs, security questions
- Passphrases, patterns
Something You Have (Possession Factor)
- Mobile phones, hardware tokens, smart cards
- SMS codes, authenticator apps
Something You Are (Inherence Factor)
- Biometric identifiers like fingerprints, facial recognition
- Voice recognition, iris scans, retinal patterns
True MFA requires at least two different categories, not just two factors from the same category (like password + security question).
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
What's the difference between Two-Factor Authentication (2FA) and Multi-Factor Authentication (MFA)?
Name and explain three common MFA methods used in modern applications.
What are the main security benefits of implementing MFA?
Explain how JWT (JSON Web Tokens) work and their structure.
What is OAuth 2.0 and how does it work?
What is Single Sign-On (SSO) and what are its benefits and challenges?
Explain Role-Based Access Control (RBAC) and its components.
What are Access Control Lists (ACLs) and when are they appropriate?
How should passwords be securely stored and what is salting?
What is CSRF (Cross-Site Request Forgery) and how can it be prevented?
Explain the security considerations for storing authentication tokens.
What is session hijacking and how can it be prevented?
How do you implement secure password reset functionality?
How do you implement and manage API key authentication securely?
What are the security implications of different password storage methods?
What is OpenID Connect and how does it extend OAuth 2.0?
How does SAML differ from OAuth 2.0/OIDC and when would you use each?
How do you implement secure session management?
What is API security and how do you secure REST APIs?
How do you prevent and detect credential stuffing attacks?
What are the security considerations for implementing social login (OAuth with third parties)?
What are JWT claims? Explain different types of claims.
How do you securely store JWT tokens on the client side?
What are refresh tokens and why are they needed?
What are the advantages and disadvantages of JWT compared to session-based authentication?
Explain the difference between signing and encryption in JWT context.
What is the 'kid' (Key ID) parameter in JWT header and when is it used?
Explain the concept of JWT audiences (aud claim) and why it's important.
What are the differences between symmetric and asymmetric algorithms for JWT signing?
How do you handle JWT token expiration gracefully in a client application?
How do you test JWT implementation properly?
Explain the security differences between SMS-based MFA and app-based TOTP. Which would you recommend and why?
What is risk-based or adaptive authentication, and how does it enhance traditional MFA?
Explain how SAML SSO integrates with MFA and describe the authentication flow.
What are the common MFA bypass techniques that attackers use, and how can they be mitigated?
How does WebAuthn/FIDO2 differ from traditional MFA methods, and what are its advantages?
What is Attribute-Based Access Control (ABAC) and how does it differ from RBAC?
What is Zero Trust Architecture and how does it impact authentication and authorization?
Explain the OAuth 2.0 PKCE (Proof Key for Code Exchange) extension and why it's important.
What are the security implications of microservices architecture for authentication and authorization?
What is OAuth 2.0 Device Authorization Grant and when would you use it?
How do you handle authentication in distributed systems with eventual consistency?
What are the security considerations when implementing passwordless authentication?
How do you implement secure cross-domain authentication for single-page applications (SPAs)?
How do you design authorization for microservices architecture?
What are the risks of improper JWT implementation and how do you mitigate them?
How do you design authentication for a high-scale distributed system?
What are the compliance considerations for authentication systems (GDPR, SOX, etc.)?
Explain the concept of Privileged Access Management (PAM) and its components.
How do you implement risk-based authentication?
How do you secure authentication in mobile applications?
What is passwordless authentication and how do you implement it securely?
What are some common security vulnerabilities with JWT and how to prevent them?
How would you implement JWT token revocation in a stateless system?
What are some best practices for implementing JWT in production?
How would you implement role-based access control (RBAC) using JWT?
What is JWT jti claim and how can it be used for token tracking?
Design an enterprise MFA strategy for a company with 10,000 employees, multiple applications, and varying security requirements. What factors would you consider?
Explain the cryptographic principles behind TOTP and HOTP, including their vulnerabilities and implementation considerations.
How would you implement MFA for a microservices architecture with service-to-service authentication requirements?
Describe the security implications and implementation challenges of biometric authentication in MFA systems.
How would you design a threat model for an MFA system and what are the most critical attack scenarios to consider?
This answer is part of Pro.
The full written answer, with the trade-offs and follow-ups an interviewer will probe.
No matches
Try a different filter or search term.
Authentication & Authorization cheatsheet
- Core Concepts01
- Authentication Methods02
- Authorization Strategies03
- Security Best Practices04
- Common Vulnerabilities05
- Advanced Topics for Senior Roles06
- Interview Tips07
- Production Tools & Libraries08
- Quick Reference09
- Interview Success Checklist10
- + 4 more inside
64 of 70 Authentication & Authorization answers are in Pro.
Full answers, code samples, and AI explanations that go simpler or deeper. Cancel anytime.
- Full answers + code
- AI explanations, simpler or deeper
- 1,000 AI credits / month
- Cancel anytime
Change topic
Pick a different technology or stack. Your current topic stays put until you choose a new one.
MEAN
MongoDB, Express, Angular, Node.jsMERN
MongoDB, Express, React, Node.jsDjango
Python Full-Stack DevelopmentRuby on Rails
Convention over ConfigurationServerless on AWS
Serverless Architecture on AWSInterviewers also test these - they're common to every stack, whichever one you picked above.
Flutter Mobile
Flutter Cross-Platform Mobile DevelopmentInterviewers also test these - they're common to every stack, whichever one you picked above.
Spring Boot
Enterprise Java Development.NET
Microsoft EcosystemVue
Vue.js, Vite, TypeScript, Tailwind, Node.jsGo Backend
Golang, gRPC, PostgreSQL, Redis, RabbitMQInterviewers also test these - they're common to every stack, whichever one you picked above.
FastAPI
Python, FastAPI, SQLAlchemy, PostgreSQLReact Native
React, TypeScript, Redux, FirebaseiOS Native
Swift, SwiftUI, UIKit, FirebaseAndroid Native
Java, Jetpack Compose, FirebaseDevOps / Platform
Docker, Kubernetes, Terraform, CI/CDInterviewers also test these - they're common to every stack, whichever one you picked above.
AI Engineer
LLMs, RAG, Agents, EvalsAI-Powered Developer
Claude Code, Copilot, Agentic WorkflowsCore SWE Interview Prep
Data structures, algorithms, OS, concurrency, networking, gitInterviewers also test these - they're common to every stack, whichever one you picked above.
Interviewers also test these - they're common to every stack, whichever one you picked above.