Nitin Agrawal
Contact -
  • Home
  • Interviews
    • InterviewFacts >
      • Secret Receipe
    • Resume Thoughts
    • Daily Coding Problems
    • BigShyft
    • Companies
    • CompanyInterviews >
      • InvestmentBanks >
        • ECS
        • Bank Of America
        • WesternUnion
        • WellsFargo
        • Deutsche Bank
      • ProductBasedCompanies >
        • CA Technologies
        • Verizon Media
        • Oracle & GoJek
        • IVY Computec
        • Nvidia
        • ClearWaterAnalytics
        • ADP
        • ServiceNow
        • Pubmatic
        • Expedia
        • Amphora
        • CDK Global
        • Delphix
        • CDK Global
        • Epic
        • Sincro-Pune
        • Whiz.AI
        • ChargePoint
        • Salesforce
        • Product Based
        • WayFair
        • Agoda
        • NPCI
        • Minicom
      • ServiceBasedCompanies >
        • SapientInterview
        • Altimetrik
        • ASG World Wide Pvt Ltd
        • Paraxel International & Pramati Technologies Pvt Ltd
        • MitraTech
        • Intelizest Coding Round
        • EPAM
        • Persistent Interview
    • Interviews Theory
    • Interview Questions >
      • 5-12 years Experienced
  • Programming Languages
    • Java Script >
      • Tutorials
      • Code Snippets
    • Reactive Programming >
      • Code Snippets
    • R
    • DataStructures >
      • LeetCode Problems >
        • Problem10
        • Problem300
      • AnagramsSet
    • Core Java >
      • GarbageCollectors
      • Codility
      • Program Arguments OR VM arguments & Environment variables
      • Profiling
      • Java Releases >
        • Java8 >
          • Performance
          • NasHorn
          • WordCount
          • Thoughts
        • Java9 >
          • ServiceLoaders
          • Lambdas
          • List Of Objects
          • Code Snippets
        • Java14 >
          • Teeing
          • Pattern
          • Semaphores
        • Java17 >
          • Switches
          • FunctionalStreams
          • Predicate
          • Consumer_Supplier
          • Collectors in Java
        • Java21 >
          • Un-named Class
          • Virtual Threads
          • Structured Concurrency
        • Java25
      • Threading >
        • ThreadsOrder
        • ProducerConsumer
        • Finalizer
        • RaceCondition
        • Executors
        • ThreadPoolExecutor
        • RecursiveTask
        • Future Or CompletableFuture
      • Important Points
      • Immutability
      • Dictionary
      • Sample Code Part 1 >
        • PatternLength
        • Serialization >
          • Kryo2
          • JAXB/XSD
          • XStream
        • MongoDB
        • Strings >
          • Reverse the String
          • Reverse the String in n/2 complexity
          • StringEditor
          • Reversing String
          • String Puzzle
          • Knuth Morris Pratt
          • Unique characters
          • Top N most occurring characters
          • Longest Common Subsequence
          • Longest Common Substring
        • New methods in Collections
        • MethodReferences
        • Complex Objects Comparator >
          • Performance
        • NIO >
          • NIO 2nd Sample
        • Date Converter
        • Minimum cost path
        • Find File
      • URL Validator
    • Julia
    • Python >
      • Decorators
      • String Formatting
      • Generators_Threads
      • JustLikeThat
    • Go >
      • Tutorial
      • CodeSnippet
      • Go Routine_Channel
      • Suggestions
    • Methodologies & Design Patterns >
      • Design Principles
      • Design Patterns >
        • TemplatePattern
        • Adapter Design Pattern
        • Proxy
        • Lazy Initialization
        • CombinatorPattern
        • Singleton >
          • Singletons
        • Strategy
  • Frameworks
    • Apache Velocity
    • React Library >
      • Tutorial
    • Spring >
      • Spring AI
      • Spring Boot >
        • CustomProperties
        • ExceptionHandling
        • Custom Beans
        • Issues
      • Quick View
    • Rest WebServices >
      • Interviews
      • Swagger
    • Cloudera BigData >
      • Ques_Ans
      • Hive
      • Apache Spark >
        • ApacheSpark Installation
        • SparkCode
        • Sample1
        • DataFrames
        • RDDs
        • SparkStreaming
        • SparkFiles
    • Integration >
      • Apache Camel
    • Testing Frameworks >
      • JUnit >
        • JUnit 5 Parameterized Test
        • JUnit Runners
      • EasyMock
      • Mockito >
        • Page 2
      • TestNG
      • Pact testing
    • Blockchain >
      • Ethereum Smart Contract
      • Blockchain Java Example
    • Microservices >
      • Messaging Formats
      • Design Patterns
    • AWS >
      • Honeycode
    • Dockers >
      • GitBash
      • Issues
      • Kubernetes
  • Databases
    • MySql
    • Oracle >
      • Interview1
      • SQL Queries
    • Elastic Search
  • Random issues
    • TOAD issue
    • System Design >
      • Cross-Region_Database_Replication
      • Real-Time SMS/USSD Mobile Money Platform
      • UPI_Payment_System_Design
      • Multi-Threaded Hit Counter Architecture
    • Architect's suggestions >
      • Comprehensive Acronyms Reference Guide
      • The Architectural Paradox: Balancing Strategic Value Against Catastrophic Risk in Enterprise Architecture
    • Dynamic loading of agents
  • Your Views

Questions in Interviews

5/6/2018

0 Comments

 
Below I will be sharing some interview questions I came across.
​But the answers of these may be correct or may not be. You have to check that once.
​Plus the kind of answer will also depends on what your interviewer wants to hear or knows about.
​So you are on your own there, if the interviewer doesn't know about your answer & s/he can reject you even though you are right.
​Will really be helpful if you can also share your thoughts on this.
Interview 1 : This question has been asked in a few interviews with Deutsche Bank, Xoriant,
​                      Sapient
like. How you will make your web service secure or how you include
​                      security in your web service?
​Answer : Like I say, it depends on what your interviewer knows the answer of this or want to
​                listen. But I think such questions are quiet abstract & the answers of these can
​                depend on many factors like what kind of security ?​               
​Questions like this are quite broad, and the ideal answer depends on factors like the application context, the nature of the resources, and the architecture (monolithic vs. microservices). Here is a structured approach covering the essential dimensions of web service security:
A) Transport-Level Security (Data in Transit)
  • HTTPS / TLS 1.3: This is the baseline for all modern web services. Enforce HTTPS across all endpoints to encrypt traffic and protect against eavesdropping or Man-in-the-Middle (MitM) attacks.
B) Authentication & Authorization (AuthN & AuthZ)
  • Use standard request headers like Authorization: Bearer <token>.
  • Standard Approach: Validate incoming tokens via framework security filters (such as Spring Security's filter chain) rather than manual interceptors. If authentication fails, return HTTP 401 Unauthorized; if permissions are insufficient, return HTTP 403 Forbidden.
  • ⚠️ Outdated Practice: Writing custom interceptor classes from scratch to manually parse custom headers and enforce roll-your-own authentication logic. Modern applications rely on standardized filter chains and existing framework security modules to avoid introducing security vulnerabilities.
C) Browser-Based Clients & Session Management
  • For web browsers, store tokens or session IDs using HttpOnly, Secure, and SameSite flags on cookies to mitigate Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF).
  • ⚠️ Outdated Practice: Relying solely on basic domain-level cookies without modern security attributes (HttpOnly, SameSite=Strict/Lax, Secure), which leaves applications vulnerable to CSRF and script injection attacks.
D) Framework Security (e.g., Spring Security)
  • Leverage enterprise security frameworks like Spring Security for standardized handling of authentication, authorization, CORS, and CSRF protection.
  • Use method-level annotations like @PreAuthorize (to check permissions before method execution) and @PostAuthorize (to check permissions or filter output after data is fetched).
E) Protocols & Identity Management
  • Standardize identity management with industry protocols like OAuth 2.0 and OpenID Connect (OIDC), integrated with Identity Providers (IdPs) like Keycloak, Azure AD, or Okta.
  • SAML 2.0 / LDAP: Common in legacy or enterprise single sign-on (SSO) setups, though modern microservices predominantly use stateless JSON Web Tokens (JWT).
  • ⚠️ Outdated Practice: Storing access roles in hardcoded .properties files or performing synchronous database lookups inside manual interceptors on every request. In high-concurrency systems, hardcoded role mapping lacks flexibility, and frequent synchronous DB checks introduce severe latency bottlenecks (which can be mitigated using token-based claims or distributed caching like Redis).
F) Data Security & Application Hardening
  • Data Protection: Encrypt sensitive payload data at rest (e.g., AES-256) and sanitize inputs using validation annotations (@Valid, @NotNull) to guard against SQL Injection and XSS attacks.
  • API Protection: Implement rate limiting (e.g., Bucket4j or API Gateway throttling) to protect against Denial of Service (DoS) attacks.
G) Microservices Architecture Considerations
  • Perimeter Defense: Use an API Gateway (e.g., Spring Cloud Gateway, Kong) to handle edge authentication, rate limiting, and token validation before traffic enters the cluster.
  • Inter-Service Security: Secure communication between internal services using mTLS (Mutual TLS) via a Service Mesh (e.g., Istio) or pass signed JWT tokens down the call chain (Token Relay pattern).
Key TakeawayAs I say, there is no silver bullet for web service security. A comprehensive solution requires a Defense-in-Depth strategy—combining secure transport (TLS), robust identity protocols (OAuth2/JWT), application-level controls (Spring Security), and edge gateways to secure both monoliths and microservices effectively. One needs to analyze many factors related to its usage, context, tools, expectations etc with lots of testing to finalize the solution. Its not an easy issue to discuss casually during 20-30 mins of discussion, millions/billions are spent around security itself.
0 Comments

    Author

    Nitin Agrawal

    Archives

    May 2018

    View my profile on LinkedIn
Powered by Create your own unique website with customizable templates.