Security interview questions

18 Security questions from the Spring bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Authentication?

Junior
  1. A.the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation
  2. B.a compact, self-contained signed token carrying claims, often used for stateless authentication across requests
  3. C.the bean defining the ordered chain of servlet filters that intercept requests to enforce protection rules
  4. D.the process of verifying who a principal is, typically by checking credentials

Answer + AI explanation with Pro

2. Which term means: "the process of verifying who a principal is, typically by checking credentials"?

Junior
  1. A.PasswordEncoder
  2. B.OAuth2
  3. C.Authentication
  4. D.Authorization

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Authentication — the process of verifying who a principal is, typically by checking credentials
  2. B.Authentication — the process of deciding whether an already-identified principal may access a resource or action
  3. C.Authentication — the delegated authorization standard letting an app obtain limited access to a user's resources without their password
  4. D.Authentication — a compact, self-contained signed token carrying claims, often used for stateless authentication across requests

Answer + AI explanation with Pro

4. What is Authorization?

Junior
  1. A.the delegated authorization standard letting an app obtain limited access to a user's resources without their password
  2. B.the process of deciding whether an already-identified principal may access a resource or action
  3. C.a compact, self-contained signed token carrying claims, often used for stateless authentication across requests
  4. D.the process of verifying who a principal is, typically by checking credentials

Answer + AI explanation with Pro

5. Which term means: "the process of deciding whether an already-identified principal may access a resource or action"?

Junior
  1. A.SecurityFilterChain
  2. B.PasswordEncoder
  3. C.Authorization
  4. D.OAuth2

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.Authorization — a compact, self-contained signed token carrying claims, often used for stateless authentication across requests
  2. B.Authorization — the delegated authorization standard letting an app obtain limited access to a user's resources without their password
  3. C.Authorization — the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation
  4. D.Authorization — the process of deciding whether an already-identified principal may access a resource or action

Answer + AI explanation with Pro

7. What is SecurityFilterChain?

Mid
  1. A.the process of deciding whether an already-identified principal may access a resource or action
  2. B.the process of verifying who a principal is, typically by checking credentials
  3. C.the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation
  4. D.the bean defining the ordered chain of servlet filters that intercept requests to enforce protection rules

Answer + AI explanation with Pro

8. Which term means: "the bean defining the ordered chain of servlet filters that intercept requests to enforce protection rules"?

Mid
  1. A.OAuth2
  2. B.Authorization
  3. C.PasswordEncoder
  4. D.SecurityFilterChain

Answer + AI explanation with Pro

9. Which statement is correct?

Mid
  1. A.SecurityFilterChain — the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation
  2. B.SecurityFilterChain — the process of verifying who a principal is, typically by checking credentials
  3. C.SecurityFilterChain — the bean defining the ordered chain of servlet filters that intercept requests to enforce protection rules
  4. D.SecurityFilterChain — the process of deciding whether an already-identified principal may access a resource or action

Answer + AI explanation with Pro

10. What is PasswordEncoder?

Mid
  1. A.the process of deciding whether an already-identified principal may access a resource or action
  2. B.the delegated authorization standard letting an app obtain limited access to a user's resources without their password
  3. C.the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation
  4. D.a compact, self-contained signed token carrying claims, often used for stateless authentication across requests

Answer + AI explanation with Pro

11. Which term means: "the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation"?

Mid
  1. A.Authorization
  2. B.JWT
  3. C.Authentication
  4. D.PasswordEncoder

Answer + AI explanation with Pro

12. Which statement is correct?

Mid
  1. A.PasswordEncoder — a compact, self-contained signed token carrying claims, often used for stateless authentication across requests
  2. B.PasswordEncoder — the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation
  3. C.PasswordEncoder — the delegated authorization standard letting an app obtain limited access to a user's resources without their password
  4. D.PasswordEncoder — the bean defining the ordered chain of servlet filters that intercept requests to enforce protection rules

Answer + AI explanation with Pro

13. What is JWT?

Senior
  1. A.the process of deciding whether an already-identified principal may access a resource or action
  2. B.a compact, self-contained signed token carrying claims, often used for stateless authentication across requests
  3. C.the process of verifying who a principal is, typically by checking credentials
  4. D.the bean defining the ordered chain of servlet filters that intercept requests to enforce protection rules

Answer + AI explanation with Pro

14. Which term means: "a compact, self-contained signed token carrying claims, often used for stateless authentication across requests"?

Senior
  1. A.Authorization
  2. B.PasswordEncoder
  3. C.SecurityFilterChain
  4. D.JWT

Answer + AI explanation with Pro

15. Which statement is correct?

Senior
  1. A.JWT — the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation
  2. B.JWT — the delegated authorization standard letting an app obtain limited access to a user's resources without their password
  3. C.JWT — a compact, self-contained signed token carrying claims, often used for stateless authentication across requests
  4. D.JWT — the process of deciding whether an already-identified principal may access a resource or action

Answer + AI explanation with Pro

16. What is OAuth2?

Senior
  1. A.the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation
  2. B.the bean defining the ordered chain of servlet filters that intercept requests to enforce protection rules
  3. C.the process of verifying who a principal is, typically by checking credentials
  4. D.the delegated authorization standard letting an app obtain limited access to a user's resources without their password

Answer + AI explanation with Pro

17. Which term means: "the delegated authorization standard letting an app obtain limited access to a user's resources without their password"?

Senior
  1. A.Authorization
  2. B.OAuth2
  3. C.JWT
  4. D.SecurityFilterChain

Answer + AI explanation with Pro

18. Which statement is correct?

Senior
  1. A.OAuth2 — the bean defining the ordered chain of servlet filters that intercept requests to enforce protection rules
  2. B.OAuth2 — the delegated authorization standard letting an app obtain limited access to a user's resources without their password
  3. C.OAuth2 — a compact, self-contained signed token carrying claims, often used for stateless authentication across requests
  4. D.OAuth2 — the abstraction for one-way hashing and verifying credentials, with BCrypt as the common implementation

Answer + AI explanation with Pro

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Security question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers