12 Auth questions from the REST API bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
B.an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
C.a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
D.a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
Answer + AI explanation with Pro
2. Which term means: "a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately"?
Junior
A.JWT
B.OAuth 2.0
C.Bearer Token
D.Refresh Token
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.Bearer Token — a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
B.Bearer Token — an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
C.Bearer Token — a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
D.Bearer Token — a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
Answer + AI explanation with Pro
4. What is JWT?
Mid
A.an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
B.a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
C.a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
D.a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
Answer + AI explanation with Pro
5. Which term means: "a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup"?
Mid
A.OAuth 2.0
B.Bearer Token
C.JWT
D.Refresh Token
Answer + AI explanation with Pro
6. Which statement is correct?
Mid
A.JWT — an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
B.JWT — a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
C.JWT — a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
D.JWT — a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
Answer + AI explanation with Pro
7. What is OAuth 2.0?
Mid
A.a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
B.an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
C.a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
D.a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
Answer + AI explanation with Pro
8. Which term means: "an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password"?
Mid
A.Bearer Token
B.JWT
C.Refresh Token
D.OAuth 2.0
Answer + AI explanation with Pro
9. Which statement is correct?
Mid
A.OAuth 2.0 — a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
B.OAuth 2.0 — a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
C.OAuth 2.0 — an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
D.OAuth 2.0 — a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
Answer + AI explanation with Pro
10. What is Refresh Token?
Senior
A.a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
B.an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
C.a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
D.a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
Answer + AI explanation with Pro
11. Which term means: "a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again"?
Senior
A.Refresh Token
B.JWT
C.Bearer Token
D.OAuth 2.0
Answer + AI explanation with Pro
12. Which statement is correct?
Senior
A.Refresh Token — a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
B.Refresh Token — a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
C.Refresh Token — an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
D.Refresh Token — a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
Answer + AI explanation with Pro
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Auth question come with Pro.