Whats process of threat modelling. Any automation work done in past. How would your team mates describe you. Explain your understanding of agile.
Application Security Interview Questions
461 application security interview questions shared by candidates
Basic Info about the company
Comparatively easy interview which covers OWASP top10
Threat model a login form, SOP, CORS etc
Type of XSS triggered in a link? My answer: every type of XSS can be triggered via link
What are the testcases for JWT token? what is the structure of JWT token ?can you bypass signature in JWT token?
can we get XSS in file upload functionality ? what is frame busting and clickjack ?
The technical questions included designing some real life feature from a security perspective.
What have you done in the past
1. AWS S3 bucket safe configuration 2. how to detect email spoofing 3. AWS logging best practices 4. scenario how to mitigate unsafe secrets stored in a git repo 5. write a python script that parses addresses from a server log and queries them against some security API to scan them (virus total, ...)
Viewing 311 - 320 interview questions