Auth interview questions

12 Auth questions from the REST API bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Bearer Token?

Junior
  1. A.a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
  2. B.an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
  3. C.a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
  4. D.a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again

Answer + AI explanation with Pro

2. Which term means: "a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately"?

Junior
  1. A.JWT
  2. B.OAuth 2.0
  3. C.Bearer Token
  4. D.Refresh Token

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Bearer Token — a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
  2. B.Bearer Token — an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
  3. C.Bearer Token — a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
  4. D.Bearer Token — a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately

Answer + AI explanation with Pro

4. What is JWT?

Mid
  1. A.an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
  2. B.a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
  3. C.a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
  4. D.a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately

Answer + AI explanation with Pro

5. Which term means: "a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup"?

Mid
  1. A.OAuth 2.0
  2. B.Bearer Token
  3. C.JWT
  4. D.Refresh Token

Answer + AI explanation with Pro

6. Which statement is correct?

Mid
  1. A.JWT — an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
  2. B.JWT — a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
  3. C.JWT — a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
  4. D.JWT — a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again

Answer + AI explanation with Pro

7. What is OAuth 2.0?

Mid
  1. A.a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
  2. B.an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
  3. C.a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
  4. D.a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again

Answer + AI explanation with Pro

8. Which term means: "an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password"?

Mid
  1. A.Bearer Token
  2. B.JWT
  3. C.Refresh Token
  4. D.OAuth 2.0

Answer + AI explanation with Pro

9. Which statement is correct?

Mid
  1. A.OAuth 2.0 — a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
  2. B.OAuth 2.0 — a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately
  3. C.OAuth 2.0 — an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
  4. D.OAuth 2.0 — a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again

Answer + AI explanation with Pro

10. What is Refresh Token?

Senior
  1. A.a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
  2. B.an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
  3. C.a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
  4. D.a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately

Answer + AI explanation with Pro

11. Which term means: "a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again"?

Senior
  1. A.Refresh Token
  2. B.JWT
  3. C.Bearer Token
  4. D.OAuth 2.0

Answer + AI explanation with Pro

12. Which statement is correct?

Senior
  1. A.Refresh Token — a compact, self-contained signed token of three base64url parts (header, payload, signature) that carries claims the server can verify without a lookup
  2. B.Refresh Token — a long-lived credential exchanged for a new short-lived access token without forcing the user to log in again
  3. C.Refresh Token — an authorization framework that lets an application obtain limited access to a user's resources via delegated access tokens, without sharing the password
  4. D.Refresh Token — a credential sent in the Authorization header that grants access to whoever possesses it, without proving identity separately

Answer + AI explanation with Pro

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Auth question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers