Skip to content
Tech Interview Prep home
Technical interview guide

Authentication vs. Authorization

Proving who you are versus what you're allowed to do — and the protocols behind each.

Read
26 min
Practice MCQs
25
Interview QA
25
Edition
v3
Editorial status
Reviewed

Scope: NIST SP 800-63 Revision 4, OWASP Cheat Sheet Series, and RFC 6750 guidance accessed 2026-08-31..

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Explain authentication versus authorization with an API example.

QA-2

How do identity proofing, authentication, federation, sessions, and authorization differ?

QA-3

Design authorization for a multi-tenant invoice API.

QA-4

Compare RBAC, ABAC, and relationship-based authorization.

QA-5

How do you secure browser session management?

QA-6

How would you validate a bearer access token at a resource server?

QA-7

Explain OAuth authorization code with PKCE.

QA-8

Compare access tokens and ID tokens.

QA-9

How do you design secure account recovery?

QA-10

How do you implement step-up authentication?

QA-11

How do you prevent user enumeration in authentication flows?

QA-12

How would you authorize service-to-service calls?

QA-13

How do you design safe administrator impersonation?

QA-14

How should authorization decisions be cached?

QA-15

How do you handle logout and token revocation?

QA-16

How do you defend cookie-authenticated APIs against CSRF?

QA-17

How do you test authorization comprehensively?

QA-18

Where must authorization run in GraphQL, WebSockets, and background jobs?

QA-19

How do you enforce field-level authorization and safe data exports?

QA-20

Design break-glass access for an operational emergency.

QA-21

How do you roll out authorization policy as code safely?

QA-22

What should authentication and authorization audit logs contain?

QA-23

Respond to a suspected session or access-token compromise.

QA-24

How do you authorize tenant migration or resource ownership transfer without race-condition leaks?

QA-25

Design identity and access management for a multi-tenant SaaS platform.