AuthN & AuthZ interview questions

45 AuthN & AuthZ questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Authentication?

Junior
  1. A.verifying who a user or system is (proving identity)
  2. B.requiring additional verification before a sensitive action despite an existing session
  3. C.Time-based One-Time Password, a short-lived code derived from a shared secret and current time
  4. D.trusting identities asserted by an external identity provider via standards like SAML or OIDC

Answer + AI explanation with Pro

2. Which term means: "verifying who a user or system is (proving identity)"?

Junior
  1. A.TOTP
  2. B.Credential stuffing
  3. C.SAML
  4. D.Authentication

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Authentication — verifying who a user or system is (proving identity)
  2. B.Authentication — trusting identities asserted by an external identity provider via standards like SAML or OIDC
  3. C.Authentication — storing a slow one-way hash of a password rather than the plaintext
  4. D.Authentication — FIDO2-based passwordless authentication using public-key credentials bound to a device and origin

Answer + AI explanation with Pro

4. What is Authorization?

Junior
  1. A.storing a slow one-way hash of a password rather than the plaintext
  2. B.determining what an authenticated identity is allowed to do
  3. C.requiring additional verification before a sensitive action despite an existing session
  4. D.verifying who a user or system is (proving identity)

Answer + AI explanation with Pro

5. Which term means: "determining what an authenticated identity is allowed to do"?

Junior
  1. A.Step-up authentication
  2. B.TOTP
  3. C.Authorization
  4. D.Multi-factor authentication (MFA)

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.Authorization — temporarily blocking logins after repeated failures to slow brute-force attacks
  2. B.Authorization — determining what an authenticated identity is allowed to do
  3. C.Authorization — requiring additional verification before a sensitive action despite an existing session
  4. D.Authorization — authenticating once to gain access to multiple independent systems

Answer + AI explanation with Pro

7. What is Multi-factor authentication (MFA)?

Junior
  1. A.temporarily blocking logins after repeated failures to slow brute-force attacks
  2. B.requiring two or more independent factors: something you know, have, or are
  3. C.Time-based One-Time Password, a short-lived code derived from a shared secret and current time
  4. D.trusting identities asserted by an external identity provider via standards like SAML or OIDC

Answer + AI explanation with Pro

8. Which term means: "requiring two or more independent factors: something you know, have, or are"?

Junior
  1. A.Federation
  2. B.Session fixation
  3. C.Multi-factor authentication (MFA)
  4. D.Token binding

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Multi-factor authentication (MFA) — FIDO2-based passwordless authentication using public-key credentials bound to a device and origin
  2. B.Multi-factor authentication (MFA) — trusting identities asserted by an external identity provider via standards like SAML or OIDC
  3. C.Multi-factor authentication (MFA) — requiring additional verification before a sensitive action despite an existing session
  4. D.Multi-factor authentication (MFA) — requiring two or more independent factors: something you know, have, or are

Answer + AI explanation with Pro

10. What is Single Sign-On (SSO)?

Junior
  1. A.XML-based standard for exchanging authentication and authorization assertions between IdP and SP
  2. B.verifying who a user or system is (proving identity)
  3. C.server-issued identifier that maintains a user's authenticated state across requests
  4. D.authenticating once to gain access to multiple independent systems

Answer + AI explanation with Pro

11. Which term means: "authenticating once to gain access to multiple independent systems"?

Junior
  1. A.Multi-factor authentication (MFA)
  2. B.Authentication
  3. C.Single Sign-On (SSO)
  4. D.Session fixation

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Single Sign-On (SSO) — authenticating once to gain access to multiple independent systems
  2. B.Single Sign-On (SSO) — server-issued identifier that maintains a user's authenticated state across requests
  3. C.Single Sign-On (SSO) — determining what an authenticated identity is allowed to do
  4. D.Single Sign-On (SSO) — Time-based One-Time Password, a short-lived code derived from a shared secret and current time

Answer + AI explanation with Pro

13. What is Session token?

Junior
  1. A.authenticating once to gain access to multiple independent systems
  2. B.server-issued identifier that maintains a user's authenticated state across requests
  3. C.FIDO2-based passwordless authentication using public-key credentials bound to a device and origin
  4. D.storing a slow one-way hash of a password rather than the plaintext

Answer + AI explanation with Pro

14. Which term means: "server-issued identifier that maintains a user's authenticated state across requests"?

Junior
  1. A.Session token
  2. B.Credential stuffing
  3. C.Password hashing
  4. D.Single Sign-On (SSO)

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.Session token — server-issued identifier that maintains a user's authenticated state across requests
  2. B.Session token — determining what an authenticated identity is allowed to do
  3. C.Session token — cryptographically tying a token to a client (e.g. TLS channel) so a stolen token cannot be replayed elsewhere
  4. D.Session token — trusting identities asserted by an external identity provider via standards like SAML or OIDC

Answer + AI explanation with Pro

16. What is Password hashing?

Junior
  1. A.forcing a victim to use a known session ID so the attacker can hijack the session after login
  2. B.requiring additional verification before a sensitive action despite an existing session
  3. C.authenticating once to gain access to multiple independent systems
  4. D.storing a slow one-way hash of a password rather than the plaintext

Answer + AI explanation with Pro

17. Which term means: "storing a slow one-way hash of a password rather than the plaintext"?

Junior
  1. A.Federation
  2. B.Password hashing
  3. C.Credential stuffing
  4. D.Session token

Answer + AI explanation with Pro

18. Which statement is correct?

Junior
  1. A.Password hashing — storing a slow one-way hash of a password rather than the plaintext
  2. B.Password hashing — server-issued identifier that maintains a user's authenticated state across requests
  3. C.Password hashing — requiring two or more independent factors: something you know, have, or are
  4. D.Password hashing — FIDO2-based passwordless authentication using public-key credentials bound to a device and origin

Answer + AI explanation with Pro

19. What is TOTP?

Mid
  1. A.forcing a victim to use a known session ID so the attacker can hijack the session after login
  2. B.XML-based standard for exchanging authentication and authorization assertions between IdP and SP
  3. C.using leaked username/password pairs from one breach to log into other services
  4. D.Time-based One-Time Password, a short-lived code derived from a shared secret and current time

Answer + AI explanation with Pro

20. Which term means: "Time-based One-Time Password, a short-lived code derived from a shared secret and current time"?

Mid
  1. A.Authentication
  2. B.Step-up authentication
  3. C.TOTP
  4. D.Session token

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.TOTP — Time-based One-Time Password, a short-lived code derived from a shared secret and current time
  2. B.TOTP — server-issued identifier that maintains a user's authenticated state across requests
  3. C.TOTP — using leaked username/password pairs from one breach to log into other services
  4. D.TOTP — XML-based standard for exchanging authentication and authorization assertions between IdP and SP

Answer + AI explanation with Pro

22. What is Credential stuffing?

Mid
  1. A.requiring two or more independent factors: something you know, have, or are
  2. B.authenticating once to gain access to multiple independent systems
  3. C.using leaked username/password pairs from one breach to log into other services
  4. D.server-issued identifier that maintains a user's authenticated state across requests

Answer + AI explanation with Pro

23. Which term means: "using leaked username/password pairs from one breach to log into other services"?

Mid
  1. A.Multi-factor authentication (MFA)
  2. B.Credential stuffing
  3. C.Step-up authentication
  4. D.Session fixation

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Credential stuffing — using leaked username/password pairs from one breach to log into other services
  2. B.Credential stuffing — authenticating once to gain access to multiple independent systems
  3. C.Credential stuffing — cryptographically tying a token to a client (e.g. TLS channel) so a stolen token cannot be replayed elsewhere
  4. D.Credential stuffing — requiring two or more independent factors: something you know, have, or are

Answer + AI explanation with Pro

25. What is Session fixation?

Mid
  1. A.verifying who a user or system is (proving identity)
  2. B.server-issued identifier that maintains a user's authenticated state across requests
  3. C.forcing a victim to use a known session ID so the attacker can hijack the session after login
  4. D.cryptographically tying a token to a client (e.g. TLS channel) so a stolen token cannot be replayed elsewhere

Answer + AI explanation with Pro

26. Which term means: "forcing a victim to use a known session ID so the attacker can hijack the session after login"?

Mid
  1. A.Session fixation
  2. B.Multi-factor authentication (MFA)
  3. C.Session token
  4. D.Federation

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Session fixation — FIDO2-based passwordless authentication using public-key credentials bound to a device and origin
  2. B.Session fixation — server-issued identifier that maintains a user's authenticated state across requests
  3. C.Session fixation — cryptographically tying a token to a client (e.g. TLS channel) so a stolen token cannot be replayed elsewhere
  4. D.Session fixation — forcing a victim to use a known session ID so the attacker can hijack the session after login

Answer + AI explanation with Pro

28. What is Account lockout?

Mid
  1. A.Time-based One-Time Password, a short-lived code derived from a shared secret and current time
  2. B.XML-based standard for exchanging authentication and authorization assertions between IdP and SP
  3. C.temporarily blocking logins after repeated failures to slow brute-force attacks
  4. D.verifying who a user or system is (proving identity)

Answer + AI explanation with Pro

29. Which term means: "temporarily blocking logins after repeated failures to slow brute-force attacks"?

Mid
  1. A.TOTP
  2. B.Credential stuffing
  3. C.Multi-factor authentication (MFA)
  4. D.Account lockout

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.Account lockout — verifying who a user or system is (proving identity)
  2. B.Account lockout — determining what an authenticated identity is allowed to do
  3. C.Account lockout — temporarily blocking logins after repeated failures to slow brute-force attacks
  4. D.Account lockout — authenticating once to gain access to multiple independent systems

Answer + AI explanation with Pro

Showing 30 of 45 AuthN & AuthZ questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every AuthN & AuthZ question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers