LearnThatStack Ace your next interview
Part of Security

Authentication & Authorization.

Start free Change topic Change
Practice · Questions

All questions

Showing of 70
Beginner 11
01

What is the difference between Authentication and Authorization?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Authentication is the process of verifying who a user is, while authorization determines what that authenticated user is allowed to do.

  • Authentication answers "Who are you?" - It's about identity verification
  • Authorization answers "What can you do?" - It's about permissions and access control
    Example:
    When you log into your email account:
  • Authentication: Entering your username/password proves you are the account owner
  • Authorization: The system then determines if you can read emails, send emails, access admin settings, etc.
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

02

What are the main types of authentication factors?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Authentication factors are categorized into three main types:

  1. Something you know (Knowledge factors)
    • Passwords, PINs, security questions
  2. Something you have (Possession factors)
    • Smartphones, hardware tokens, smart cards
  3. Something you are (Inherence factors)
    • Biometrics: fingerprints, facial recognition, retina scans
      Multi-Factor Authentication (MFA) combines two or more of these factors for enhanced security.
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

03

What is session management and why is it important?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Session management is the process of securely handling user sessions from login to logout. It maintains the user's authenticated state across multiple requests without requiring re-authentication for each action.
Key components:

  • Session creation: Generated after successful authentication
  • Session storage: Server-side storage of session data
  • Session validation: Checking session validity on each request
  • Session termination: Proper cleanup on logout or timeout
    Importance:
  • Provides seamless user experience
  • Maintains security state
  • Prevents unauthorized access
  • Enables proper audit trails
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

04

What is the principle of least privilege?

Part of Pro
05

What is Multi-Factor Authentication (MFA) and when should it be used?

Part of Pro
06

Explain the different authentication factors and provide examples of each.

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Authentication factors are categorized into three types:

  1. Something you know (Knowledge factors):
    • Passwords, PINs, security questions
    • Passphrases, secret keys
  2. Something you have (Possession factors):
    • Smartphones with authenticator apps
    • Hardware tokens, smart cards
    • SMS tokens, email confirmations
  3. Something you are (Inherence factors):
    • Fingerprints, facial recognition
    • Retina scans, voice patterns
    • Behavioral biometrics (typing patterns)
      Multi-Factor Authentication (MFA) combines two or more of these factors to enhance security. For example, using a password (knowledge) + SMS code (possession) provides stronger security than password alone.
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

07

What are the three parts of a JWT token? Explain each part.

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Header:

{
  "alg": "HS256",
  "typ": "JWT"
}

Contains metadata about the token, including the signing algorithm and token type.

Payload:

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022,
  "exp": 1516242622
}

Contains claims - statements about an entity (typically the user) and additional data. Claims can be registered, public, or private.

Signature:

HMACSHA256(
  base64UrlEncode(header) + "." +
  base64UrlEncode(payload),
  secret
)

Used to verify that the sender of the JWT is who it says it is and to ensure that the message wasn't changed along the way.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

08

What are the three main categories of authentication factors?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

The three main categories of authentication factors are:

  1. Something You Know (Knowledge Factor)

    • Passwords, PINs, security questions
    • Passphrases, patterns
  2. Something You Have (Possession Factor)

    • Mobile phones, hardware tokens, smart cards
    • SMS codes, authenticator apps
  3. Something You Are (Inherence Factor)

    • Biometric identifiers like fingerprints, facial recognition
    • Voice recognition, iris scans, retinal patterns

True MFA requires at least two different categories, not just two factors from the same category (like password + security question).

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

09

What's the difference between Two-Factor Authentication (2FA) and Multi-Factor Authentication (MFA)?

Part of Pro
10

Name and explain three common MFA methods used in modern applications.

Part of Pro
11

What are the main security benefits of implementing MFA?

Part of Pro
Intermediate 33
12

Explain how JWT (JSON Web Tokens) work and their structure.

Part of Pro
13

What is OAuth 2.0 and how does it work?

Part of Pro
14

What is Single Sign-On (SSO) and what are its benefits and challenges?

Part of Pro
15

Explain Role-Based Access Control (RBAC) and its components.

Part of Pro
16

What are Access Control Lists (ACLs) and when are they appropriate?

Part of Pro
17

How should passwords be securely stored and what is salting?

Part of Pro
18

What is CSRF (Cross-Site Request Forgery) and how can it be prevented?

Part of Pro
19

Explain the security considerations for storing authentication tokens.

Part of Pro
20

What is session hijacking and how can it be prevented?

Part of Pro
21

How do you implement secure password reset functionality?

Part of Pro
22

How do you implement and manage API key authentication securely?

Part of Pro
23

What are the security implications of different password storage methods?

Part of Pro
24

What is OpenID Connect and how does it extend OAuth 2.0?

Part of Pro
25

How does SAML differ from OAuth 2.0/OIDC and when would you use each?

Part of Pro
26

How do you implement secure session management?

Part of Pro
27

What is API security and how do you secure REST APIs?

Part of Pro
28

How do you prevent and detect credential stuffing attacks?

Part of Pro
29

What are the security considerations for implementing social login (OAuth with third parties)?

Part of Pro
30

What are JWT claims? Explain different types of claims.

Part of Pro
31

How do you securely store JWT tokens on the client side?

Part of Pro
32

What are refresh tokens and why are they needed?

Part of Pro
33

What are the advantages and disadvantages of JWT compared to session-based authentication?

Part of Pro
34

Explain the difference between signing and encryption in JWT context.

Part of Pro
35

What is the 'kid' (Key ID) parameter in JWT header and when is it used?

Part of Pro
36

Explain the concept of JWT audiences (aud claim) and why it's important.

Part of Pro
37

What are the differences between symmetric and asymmetric algorithms for JWT signing?

Part of Pro
38

How do you handle JWT token expiration gracefully in a client application?

Part of Pro
39

How do you test JWT implementation properly?

Part of Pro
40

Explain the security differences between SMS-based MFA and app-based TOTP. Which would you recommend and why?

Part of Pro
41

What is risk-based or adaptive authentication, and how does it enhance traditional MFA?

Part of Pro
42

Explain how SAML SSO integrates with MFA and describe the authentication flow.

Part of Pro
43

What are the common MFA bypass techniques that attackers use, and how can they be mitigated?

Part of Pro
44

How does WebAuthn/FIDO2 differ from traditional MFA methods, and what are its advantages?

Part of Pro
Expert 26
45

What is Attribute-Based Access Control (ABAC) and how does it differ from RBAC?

Part of Pro
46

What is Zero Trust Architecture and how does it impact authentication and authorization?

Part of Pro
47

Explain the OAuth 2.0 PKCE (Proof Key for Code Exchange) extension and why it's important.

Part of Pro
48

What are the security implications of microservices architecture for authentication and authorization?

Part of Pro
49

What is OAuth 2.0 Device Authorization Grant and when would you use it?

Part of Pro
50

How do you handle authentication in distributed systems with eventual consistency?

Part of Pro
51

What are the security considerations when implementing passwordless authentication?

Part of Pro
52

How do you implement secure cross-domain authentication for single-page applications (SPAs)?

Part of Pro
53

How do you design authorization for microservices architecture?

Part of Pro
54

What are the risks of improper JWT implementation and how do you mitigate them?

Part of Pro
55

How do you design authentication for a high-scale distributed system?

Part of Pro
56

What are the compliance considerations for authentication systems (GDPR, SOX, etc.)?

Part of Pro
57

Explain the concept of Privileged Access Management (PAM) and its components.

Part of Pro
58

How do you implement risk-based authentication?

Part of Pro
59

How do you secure authentication in mobile applications?

Part of Pro
60

What is passwordless authentication and how do you implement it securely?

Part of Pro
61

What are some common security vulnerabilities with JWT and how to prevent them?

Part of Pro
62

How would you implement JWT token revocation in a stateless system?

Part of Pro
63

What are some best practices for implementing JWT in production?

Part of Pro
64

How would you implement role-based access control (RBAC) using JWT?

Part of Pro
65

What is JWT jti claim and how can it be used for token tracking?

Part of Pro
66

Design an enterprise MFA strategy for a company with 10,000 employees, multiple applications, and varying security requirements. What factors would you consider?

Part of Pro
67

Explain the cryptographic principles behind TOTP and HOTP, including their vulnerabilities and implementation considerations.

Part of Pro
68

How would you implement MFA for a microservices architecture with service-to-service authentication requirements?

Part of Pro
69

Describe the security implications and implementation challenges of biometric authentication in MFA systems.

Part of Pro
70

How would you design a threat model for an MFA system and what are the most critical attack scenarios to consider?

Part of Pro

No matches

Try a different filter or search term.

Know someone prepping for Authentication & Authorization? Send them this set.
Pro · $10/mo

64 of 70 Authentication & Authorization answers are in Pro.

Full answers, code samples, and AI explanations that go simpler or deeper. Cancel anytime.

  • Full answers + code
  • AI explanations, simpler or deeper
  • 1,000 AI credits / month
  • Cancel anytime

Change topic

Pick a different technology or stack. Your current topic stays put until you choose a new one.

Technologies
No technologies match “”.
Cross-cutting topics
No topics match “”.
By role
Stacks & frameworks

MEAN

MongoDB, Express, Angular, Node.js

MERN

MongoDB, Express, React, Node.js

LAMP

Linux, Apache, MySQL, PHP

Django

Python Full-Stack Development

Ruby on Rails

Convention over Configuration

Serverless on AWS

Serverless Architecture on AWS

Flutter Mobile

Flutter Cross-Platform Mobile Development

Spring Boot

Enterprise Java Development

.NET

Microsoft Ecosystem

Vue

Vue.js, Vite, TypeScript, Tailwind, Node.js

Go Backend

Golang, gRPC, PostgreSQL, Redis, RabbitMQ

FastAPI

Python, FastAPI, SQLAlchemy, PostgreSQL

React Native

React, TypeScript, Redux, Firebase

iOS Native

Swift, SwiftUI, UIKit, Firebase

Android Native

Java, Jetpack Compose, Firebase

DevOps / Platform

Docker, Kubernetes, Terraform, CI/CD

AI Engineer

LLMs, RAG, Agents, Evals

AI-Powered Developer

Claude Code, Copilot, Agentic Workflows

Core SWE Interview Prep

Data structures, algorithms, OS, concurrency, networking, git