Interview questions · Book 07
Security interview questions
228 questions from 57 pages, each with a short answer. Say your answer first, then open the question to check it.
p. 1 · 4 questions
ABAC
1
What is ABAC?
ABAC is an authorization model that allows or denies each request by checking attributes of the user, the resource, the action and the context against policies.
2
What is the difference between ABAC and RBAC?
RBAC grants permissions through roles such as admin or editor. ABAC evaluates attributes of the user, the resource and the context in policies, so it can express conditions such as ownership, department or time of day that roles alone can't.
3
What is an example of ABAC?
A hospital rule that lets doctors read records only for patients in their own department and only while on shift, or a document app that lets users edit only the drafts they own. Each rule combines attributes instead of naming a role.
4
Which tools are used for ABAC?
Policy engines such as Open Policy Agent, with its Rego language, and Cedar, used by Amazon Verified Permissions, as well as the older XACML standard. Cloud IAM systems also support attribute conditions, such as AWS policies based on tags.
p. 2 · 4 questions
API Key
1
What is an API key?
An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
2
What is the difference between an API key and an OAuth token?
An API key is a long-lived secret that identifies an application or project. An OAuth access token is usually short-lived, represents a specific user's permission, and is limited to the scopes that user approved.
3
Is it safe to put an API key in front-end JavaScript?
Not for secret keys. Anything shipped to a browser or mobile app can be read by users, so secret keys belong on a server that calls the API on the client's behalf; some providers issue publishable keys meant for front-end use, which should still be restricted by domain.
4
What should I do if I leaked an API key?
Revoke or rotate the key immediately in the provider's dashboard, then replace it wherever it is used. Deleting it in a later Git commit is not enough, because it remains in the repository history and may already have been copied by automated scanners.
p. 3 · 4 questions
Authentication
1
What is authentication?
Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
2
What is the difference between authentication and authorization?
Authentication verifies who a user is, for example by checking a password or passkey. Authorization happens afterward and decides what that verified user is allowed to access or change.
3
What is a passkey?
A passkey is a login credential based on public-key cryptography, stored on a device or in a password manager and unlocked with a fingerprint, face scan, or PIN. The private key never leaves the device and only works on the real website, and the server stores only a public key, so passkeys resist phishing and are useless to attackers who steal the server's database.
4
What does HTTP 401 mean?
Despite its name,
401 Unauthorizedmeans the request lacks valid authentication, such as a missing or expired token. When the user is authenticated but not allowed to do something, the correct status is403 Forbidden.
p. 5 · 4 questions
bcrypt
1
What is bcrypt?
bcrypt is a password-hashing function that adds a random salt and is deliberately slow, so stolen password hashes are very expensive to crack by guessing.
2
Is bcrypt still secure?
Yes. With a cost factor of at least 10 it is still considered acceptable and protects millions of accounts. For new systems, Argon2id is generally recommended because each guess also needs a large amount of memory, which slows down attacks on GPUs.
3
What is the difference between bcrypt and SHA-256?
SHA-256 is a fast, general-purpose hash for checksums, signatures and data integrity. bcrypt is a deliberately slow password hash with a built-in salt, so attackers can test far fewer guesses per second against stolen hashes.
4
Can a bcrypt hash be decrypted?
No. bcrypt is one-way. To check a login, the library hashes the entered password again with the salt and cost stored in the hash and compares the two results.
p. 6 · 4 questions
Brute-Force Attack
1
What is a brute-force attack?
A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
2
How do websites protect against brute-force attacks?
They limit how many sign-in attempts can be made per account and per IP address, add delays or temporary lockouts after failures, and require multi-factor authentication. On the storage side, they hash passwords with slow, salted algorithms so a stolen database is expensive to crack.
3
What is the difference between brute force and credential stuffing?
Brute force guesses passwords that the attacker does not know yet. Credential stuffing reuses real username and password pairs leaked in other breaches, betting that people reuse the same password on several sites.
4
How long does it take to brute-force a password?
It depends on the password's length and randomness and on how it is stored. A short password protected by a fast hash can fall in seconds, while a long random passphrase stored with Argon2id or bcrypt would take far longer than a human lifetime.
p. 7 · 4 questions
Bug Bounty
1
What is a bug bounty?
A bug bounty is a program in which an organization rewards outside security researchers for finding and responsibly reporting vulnerabilities in its systems.
2
What is the difference between a bug bounty and penetration testing?
A penetration test hires a team to test a fixed scope for a fixed time and is paid regardless of the results. A bug bounty is ongoing, open to many researchers and pays only for valid, new vulnerabilities.
3
Is bug bounty hunting legal?
Within an official program's scope and rules, yes, and safe harbor terms promise no legal action. Testing systems without permission, or outside the published scope, can break computer crime laws even when the intent is good.
4
How do you start bug bounty hunting?
Learn how common web vulnerabilities work, for example from the OWASP Top 10, practice on deliberately vulnerable labs and capture-the-flag challenges, and read publicly disclosed reports. Then choose a program with a broad scope and follow its rules exactly.