Why does statelessness help an API scale, and where does session state live instead?Any server can take any request, so you don't need sticky sessions. State moves to the client, such as a token, or to a shared store like a database or cache.
How would you make a GET response cacheable, and how does the client check it is still fresh?Cache-Control with max-age, plus an ETag or Last-Modified. The client sends If-None-Match and gets 304 Not Modified if nothing changed.
How would you model an action like cancelling an order without putting a verb in the URL?Treat it as a state change on a resource, like PATCH on the order's status or POST to a cancellation sub-resource. Pick one and say why.
What you can say
An API is RESTful when it follows the REST architectural constraints. Using HTTP with JSON doesn't get you there by itself.
The central one is the uniform interface. URLs identify resources, clients change them through representations, messages describe themselves, and responses carry links, which is HATEOAS.
Every request is stateless, so it carries everything the server needs, and every response says whether it can be cached.
It's client-server with a clear split of concerns, it can sit behind layers like proxies and gateways, and code on demand is the one optional constraint.
In practice that shows up as noun-based URLs, HTTP methods and status codes used for what they mean, and support for more than one representation, like JSON or XML.
Most APIs called REST skip HATEOAS and have clients hardcode URLs, so strictly they're REST-like. I'd say that openly rather than claim full REST.
Weak answers to avoid
Says REST just means HTTP plus JSONREST is a set of architectural constraints, not a protocol or a format. Name the constraints, then show how HTTP methods, URLs and status codes map onto them.
Recites the constraints with no reason for anyA memorized list shows recall, not understanding. Say what each one buys, for example statelessness lets any server take any request, and caching cuts load.
Calls a POST-only API with /getUser URLs RESTfulThat is RPC over HTTP. URLs should name resources as nouns, the HTTP method says what to do, and the status code reports the result.
Claims full REST while ignoring HATEOASHATEOAS is part of the uniform interface. Admit that most APIs skip it and hardcode URLs, and explain the trade instead of overclaiming.
Interview lens
Likely follow-ups, what you can say, and the weak answers to avoid.