HTTP/HTTPS
HTTP/HTTPS
Beginner
Q1: What is HTTP?
HTTP (Hypertext Transfer Protocol) is the protocol used to fetch resources such as HTML pages, images, JSON, and other web content.
Q2: What is HTTPS?
HTTPS is HTTP over TLS/SSL, meaning the HTTP traffic is encrypted and authenticated.
Q3: Why is HTTPS important?
HTTPS protects data in transit from eavesdropping, tampering, and impersonation.
Q4: What is a URL?
A URL (Uniform Resource Locator) is the address used to identify a web resource, such as https://example.com/page.
Q5: What is a URI?
A URI (Uniform Resource Identifier) is a string that identifies a resource, and a URL is a type of URI.
Q6: What is a scheme?
A scheme is the protocol portion of a URL, such as http or https.
Q7: What is a host?
A host is the server name or IP address that receives the request, such as example.com.
Q8: What is a port?
A port is a communication endpoint, such as 80 for HTTP and 443 for HTTPS.
Q9: What is a path?
A path identifies a resource location on the server, such as /products/123.
Q10: What is a query string?
A query string is the part of a URL after ? used to send parameters, such as ?page=2&sort=asc.
Q11: What is a fragment?
A fragment is the part after # and is mainly used by the client for page anchors, such as #section-2.
Q12: What is a client?
A client is the program or browser that sends an HTTP request.
Q13: What is a server?
A server is the program that receives the request and returns a response.
Q14: What is an HTTP request?
An HTTP request is a message sent by the client to the server asking for a resource or action.
Q15: What is an HTTP response?
An HTTP response is the server’s answer to the client’s request.
Q16: What is a status code?
A status code tells the client the result of the request, such as 200 OK or 404 Not Found.
Q17: What is a 200 status code?
200 OK means the request succeeded.
Q18: What is a 201 status code?
201 Created means the request created a new resource.
Q19: What is a 204 status code?
204 No Content means the request succeeded but there is no response body.
Q20: What is a 301 status code?
301 Moved Permanently indicates the resource has permanently moved to another URL.
Q21: What is a 302 status code?
302 Found means the resource is temporarily at a different location.
Q22: What is a 304 status code?
304 Not Modified tells the client the cached version is still valid.
Q23: What is a 400 status code?
400 Bad Request means the request is malformed or invalid.
Q24: What is a 401 status code?
401 Unauthorized means authentication is required.
Q25: What is a 403 status code?
403 Forbidden means the client is authenticated but not allowed to access the resource.
Q26: What is a 404 status code?
404 Not Found means the resource does not exist.
Q27: What is a 405 status code?
405 Method Not Allowed means the HTTP method is not supported for that endpoint.
Q28: What is a 500 status code?
500 Internal Server Error indicates the server encountered an unexpected error.
Q29: What is a 503 status code?
503 Service Unavailable means the server is temporarily unable to handle the request.
Q30: What is HTTP method?
An HTTP method defines the action to perform, such as GET, POST, PUT, DELETE, PATCH.
Q31: What is GET?
GET is used to retrieve a resource without changing the server state.
Q32: What is POST?
POST is used to submit data to create or process a resource.
Q33: What is PUT?
PUT replaces or creates a resource at a known URI.
Q34: What is PATCH?
PATCH applies partial updates to a resource.
Q35: What is DELETE?
DELETE removes a resource.
Q36: What is HEAD?
HEAD requests the headers for a resource without fetching the body.
Q37: What is OPTIONS?
OPTIONS asks the server which methods are allowed for a resource.
Q38: What is TRACE?
TRACE echoes the request back to the client for debugging.
Q39: What is CONNECT?
CONNECT establishes a tunnel, often used by proxies and HTTPS tunneling.
Q40: What is a request header?
A request header contains metadata about the request, such as Host, User-Agent, Accept, and Authorization.
Q41: What is a response header?
A response header contains metadata about the response, such as Content-Type, Server, Cache-Control, and Location.
Q42: What is a request body?
The request body contains data sent to the server, such as JSON, form fields, or file content.
Q43: What is a response body?
The response body contains the actual resource data sent back to the client.
Q44: What is an HTTP header?
An HTTP header is metadata sent as part of a request or response.
Q45: What is Host header?
The Host header tells the server which virtual host is being requested.
Q46: What is User-Agent?
The User-Agent header identifies the client software, such as a browser or API client.
Q47: What is Accept header?
The Accept header tells the server what content types the client supports.
Q48: What is Content-Type?
Content-Type tells the client or server what kind of data is present in the body.
Q49: What is Authorization header?
The Authorization header carries credentials such as tokens or basic auth credentials.
Q50: What is Cookie header?
The Cookie header sends state from the client back to the server.
Q51: What is Set-Cookie?
Set-Cookie is a response header used to create or update a browser cookie.
Q52: What is caching?
Caching stores copies of response data to reduce latency and server load.
Q53: What is Cache-Control?
Cache-Control is a response or request header that controls caching behavior.
Q54: What is ETag?
ETag is a unique identifier for a resource version, used for conditional requests.
Q55: What is If-None-Match?
If-None-Match allows a client to ask the server for the resource only if it has changed.
Q56: What is Last-Modified?
Last-Modified is a header giving the last modification time of a resource.
Q57: What is If-Modified-Since?
If-Modified-Since allows the client to validate cached resources.
Q58: What is a browser cache?
A browser cache stores HTTP responses locally to avoid repeated network requests.
Q59: What is a CDN?
A CDN (Content Delivery Network) caches content closer to users to improve delivery speed.
Q60: What is a reverse proxy?
A reverse proxy sits in front of servers and forwards client requests to backend services.
Q61: What is a forward proxy?
A forward proxy handles requests on behalf of clients, often for filtering or caching.
Q62: What is statelessness in HTTP?
HTTP is stateless, meaning each request is independent and does not inherently retain previous request state.
Q63: Why is HTTP stateless?
Because it is designed to be simple, scalable, and independent across requests.
Q64: What is a session?
A session is a way to maintain state across multiple HTTP requests, usually using cookies or tokens.
Q65: What is a cookie?
A cookie is a small piece of client-side state stored by the browser and sent with future requests.
Q66: Why are cookies used?
Cookies allow the server to remember preferences, login state, and session information.
Q67: What is session management?
Session management is the technique for associating a user or client with a stateful session.
Q68: What is a token?
A token is a credential or identifier used to authenticate or authorize requests, often in headers or cookies.
Q69: What is a bearer token?
A bearer token is a token that grants access to whoever possesses it, so it must be protected.
Q70: What is Basic Auth?
Basic Auth sends a username and password encoded as base64 inside the Authorization header.
Q71: Why is Basic Auth not ideal?
It is not very secure unless used over HTTPS and is weaker than modern token-based auth.
Q72: What is a REST API?
A REST API is a web API that uses HTTP methods and resources to perform operations.
Q73: What is an endpoint?
An endpoint is a URL or path exposed by a service.
Q74: What is API versioning?
API versioning allows multiple versions of an API to coexist as the system evolves.
Q75: What is JSON?
JSON is a common data format used in HTTP request and response bodies.
Q76: What is XML?
XML is another structured document format often used in older APIs.
Q77: What is content negotiation?
Content negotiation lets client and server agree on the best representation format, such as JSON vs XML.
Q78: What is Accept-Encoding?
Accept-Encoding tells the server what compression formats the client supports, such as gzip or br.
Q79: What is gzip?
gzip is a common compression format used to reduce HTTP payload size.
Q80: What is TLS?
TLS (Transport Layer Security) provides encryption, integrity, and authentication for network traffic.
Q81: Why does HTTPS use TLS?
Because it protects HTTP data during transmission.
Q82: What is a certificate?
A certificate is a digitally signed document used to prove identity in TLS.
Q83: What is a certificate authority?
A certificate authority (CA) issues and signs digital certificates.
Q84: What is certificate validation?
Certificate validation confirms that a presented server certificate is trusted and matches the domain.
Q85: What is a self-signed certificate?
A self-signed certificate is signed by itself rather than by a trusted authority.
Q86: What is a certificate chain?
A certificate chain is the sequence of certificates used to establish trust to a root CA.
Q87: What is the TLS handshake?
The TLS handshake is the negotiation that establishes encrypted communication between client and server.
Q88: What is the server name indication?
SNI is an extension that allows a client to specify the hostname it wants to connect to during the TLS handshake.
Q89: Why is SNI important?
It allows multiple HTTPS sites to share the same IP address and certificate selection.
Q90: What is HSTS?
HSTS (HTTP Strict Transport Security) tells browsers to always use HTTPS for a domain.
Q91: Why is HSTS useful?
It prevents downgrade attacks and makes HTTPS enforcement more reliable.
Q92: What is a redirect?
A redirect tells the browser to fetch another URL, usually using 3xx status codes.
Q93: What is a relative URL?
A relative URL is a path relative to the current resource, such as /login.
Q94: What is an absolute URL?
An absolute URL includes the full scheme, host, and path, such as https://example.com/login.
Q95: What is a web browser?
A web browser is a client that renders HTML and makes HTTP requests to web servers.
Q96: What is a web server?
A web server processes HTTP requests and returns resources or data.
Q97: What is a reverse proxy server?
A reverse proxy accepts traffic and forwards it to one or more application servers.
Q98: What is CORS?
CORS (Cross-Origin Resource Sharing) controls which websites can access a resource from another origin.
Q99: What is Same-Origin Policy?
Same-Origin Policy restricts scripts from reading data across origins unless allowed by CORS.
Q100: What is an origin?
An origin is the scheme, host, and port combination, such as https://app.example.com.
Q101: What is a preflight request?
A preflight request is an OPTIONS request sent before a cross-origin request to check allowed methods and headers.
Q102: What is a non-simple request?
A non-simple request is a cross-origin request that uses custom headers, credentials, or non-standard methods.
Q103: What is the role of cookies in CORS?
Cookies are subject to origin restrictions and often require credentials mode to be explicitly enabled.
Q104: Why do browsers enforce CORS?
To protect users and prevent unauthorized cross-site data access.
Q105: What is session fixation?
Session fixation is when an attacker forces a user to use a known session ID to gain unauthorized access.
Q106: Why is HTTPS needed for login flows?
Because credentials and session tokens must not be exposed across the network.
Q107: What is CSRF?
CSRF (Cross-Site Request Forgery) tricks a user’s browser into sending a request to a trusted site.
Q108: What is XSS?
XSS (Cross-Site Scripting) injects malicious scripts into a website or application.
Q109: What is the role of HTTP in XSS?
HTTP alone does not prevent injection; security must be handled in the application and content policies.
Q110: What is a same-site cookie?
A same-site cookie restricts cross-site sending of cookies, reducing CSRF risk.
Q111: What is secure flag on a cookie?
The Secure flag ensures cookies are only sent over HTTPS.
Q112: What is HttpOnly?
HttpOnly prevents JavaScript from reading a cookie, reducing XSS impact.
Q113: What is the difference between HTTP and HTTPS at the socket level?
HTTPS encrypts the transport layer using TLS, while HTTP does not.
Q114: Why is redirecting HTTP to HTTPS important?
It ensures clients consistently use encryption and reduces accidental insecure access.
Q115: What is HTTP/1.1?
HTTP/1.1 is the widely used HTTP version with features like persistent connections and pipelining.
Q116: What is HTTP/2?
HTTP/2 improves performance with multiplexing, binary framing, header compression, and server push.
Q117: What is HTTP/3?
HTTP/3 uses QUIC instead of TCP and offers better multiplexing and lower latency.
Q118: Why is HTTP/2 faster than HTTP/1.1?
It avoids head-of-line blocking and reduces header overhead by multiplexing many streams over one connection.
Q119: What is multiplexing?
Multiplexing allows many requests and responses to share one TCP connection.
Q120: What is header compression?
Header compression reduces the size of repeated HTTP headers to save bandwidth and latency.
Intermediate
Q121: What is a keep-alive connection?
A keep-alive connection reuses the same TCP connection for multiple HTTP requests.
Q122: What is connection reuse?
Connection reuse reduces the overhead of opening new TCP connections for every request.
Q123: What is request pipelining?
Pipelining allows multiple HTTP requests to be sent without waiting for each response, though it is limited in HTTP/1.1.
Q124: What is head-of-line blocking?
Head-of-line blocking occurs when one slow response blocks others in the same connection.
Q125: What is connection coalescing?
Connection coalescing combines multiple network flows or connections to reduce setup costs.
Q126: What is the TCP handshake?
The TCP handshake is the three-step process used before data exchange begins: SYN, SYN-ACK, ACK.
Q127: How does HTTP relate to TCP?
HTTP runs on top of TCP, which provides reliable ordered delivery of bytes.
Q128: Why is HTTPS more expensive than HTTP?
It adds TLS negotiation, certificate validation, and crypto overhead.
Q129: What is a TLS certificate chain validation?
It is the process of validating the server cert through intermediate and root certificates.
Q130: What is OCSP?
OCSP (Online Certificate Status Protocol) checks whether a certificate has been revoked.
Q131: What is OCSP stapling?
OCSP stapling allows the server to provide certificate revocation status during the TLS handshake.
Q132: What is a certificate pinning?
Certificate pinning binds a client to a specific certificate or public key to reduce MITM risk.
Q133: What is certificate rotation?
Certificate rotation is the process of issuing and deploying a new certificate before the old one expires.
Q134: What is a wildcard certificate?
A wildcard certificate covers multiple subdomains under a single domain, such as *.example.com.
Q135: What is a SAN certificate?
A SAN certificate includes multiple subject alternative names, allowing many domains in one cert.
Q136: What is a redirect loop?
A redirect loop happens when a series of redirects repeatedly sends the client back and forth.
Q137: What is a canonical URL?
A canonical URL is the preferred URL for a resource to avoid duplicates and SEO issues.
Q138: What is cache validation?
Cache validation checks whether a cached response is still fresh or stale.
Q139: What is stale-while-revalidate?
It allows a stale resource to be served while an updated copy is revalidated in the background.
Q140: What is stale-if-error?
It allows stale content to be returned when the backend fails.
Q141: What is Vary header?
The Vary header tells caches that the response varies by request headers such as Accept-Encoding or User-Agent.
Q142: What is a conditional request?
A conditional request asks the server to respond only if the resource has changed, saving bandwidth.
Q143: What is a 206 Partial Content response?
206 Partial Content is used when a client requests only part of a resource, such as a range.
Q144: What is Range header?
The Range header asks the server to return a byte range of the resource.
Q145: What is Accept-Language?
Accept-Language tells the server which human language the client prefers.
Q146: What is content encoding?
Content encoding describes how the representation body is encoded, such as gzip.
Q147: What is Transfer-Encoding?
Transfer-Encoding defines how the message body is framed, such as chunked encoding.
Q148: What is chunked transfer encoding?
Chunked encoding splits the body into chunks so the server can stream it without knowing the full size ahead of time.
Q149: What is a payload?
A payload is the data being carried in the request or response body.
Q150: What is a request/response queue?
A queue holds incoming HTTP requests or outgoing responses waiting for processing or delivery.
Q151: What is a load balancer and how does it relate to HTTP?
A load balancer distributes HTTP requests across multiple application instances.
Q152: Why does HTTP need compression?
Compression reduces payload size, improving latency and bandwidth consumption.
Q153: What is HTTP/2 server push?
Server push sends resources proactively to the client before it asks for them.
Q154: Why is server push controversial?
It can waste bandwidth if the client never uses the pushed assets.
Q155: What is a character set?
A character set defines how text bytes are mapped to characters, such as UTF-8.
Q156: What is Content-Language?
Content-Language tells the client which language the content is written in.
Q157: What is a web API contract?
A web API contract defines the expected endpoints, data formats, methods, and status codes.
Q158: What is an idempotent request?
An idempotent request produces the same result when repeated, such as GET or DELETE in many patterns.
Q159: What is a safe method?
A safe method is one that does not modify server state, such as GET and HEAD.
Q160: What is a non-idempotent method?
A non-idempotent method may have side effects, such as POST or PATCH.
Q161: What is rate limiting?
Rate limiting restricts how often a client can call an API or endpoint.
Q162: Why is rate limiting important?
It prevents abuse, service degradation, and resource exhaustion.
Q163: What is retry-after?
Retry-After tells clients how long to wait before retrying a request after a server-side condition.
Q164: What is concurrency in HTTP?
Concurrency refers to multiple requests being processed at the same time by the client or server.
Q165: What is long polling?
Long polling keeps a request open until new data becomes available, then returns it.
Q166: What is WebSocket?
WebSocket is a protocol that provides continuous bidirectional communication with a persistent TCP socket.
Q167: Why is WebSocket different from HTTP?
HTTP is request/response-based; WebSocket is full-duplex and stateful.
Q168: What is HTTP upgrade?
HTTP upgrade allows a client to switch protocols, such as from HTTP to WebSocket.
Q169: What is a proxy protocol?
A proxy protocol adds metadata about the original client connection to requests forwarded through a proxy.
Q170: What is a connection limit?
A connection limit defines how many simultaneous connections a server or load balancer will handle.
Q171: What is certificate transparency?
Certificate transparency logs public certificates so browsers and clients can detect malicious or unintended issuance.
Q172: What is OCSP responder?
An OCSP responder answers certificate revocation checks for certificate validation.
Q173: What is H2C?
H2C is HTTP/2 without TLS, used in trusted internal environments.
Q174: What is HTTP/3 over QUIC?
HTTP/3 uses QUIC to reduce connection setup latency and improve recovery under packet loss.
Q175: What is the difference between TLS and HTTPS?
TLS is the encryption mechanism; HTTPS is HTTP transported using TLS.
Q176: What is a TLS session resumption?
Session resumption reuses a previous TLS handshake state to reduce handshake overhead.
Q177: What is a proof of domain ownership?
A proof of domain ownership is a mechanism used during certificate issuance to confirm the requester controls the domain.
Q178: What is TLS ALPN?
ALPN (Application-Layer Protocol Negotiation) allows a TLS client and server to negotiate protocol versions such as HTTP/1.1, HTTP/2, or HTTP/3.
Q179: What is CDN edge logic?
CDN edge logic decides how to route, cache, or rewrite requests close to users.
Q180: What is an origin server?
An origin server is the original source server for the content, behind caches and proxies.
Q181: What is an API gateway?
An API gateway is a layer that handles routing, authentication, rate limiting, and transformation of API traffic.
Q182: Why is HTTP important in microservices?
Microservices communicate over HTTP or HTTPS for modularity, interoperability, and standardization.
Q183: What is a health check endpoint?
A health check endpoint confirms whether a service is running and ready to receive requests.
Q184: What is a readiness endpoint?
A readiness endpoint tells a load balancer or orchestrator whether the service is ready to receive traffic.
Q185: What is a liveness endpoint?
A liveness endpoint tells whether an application is alive and not stuck or deadlocked.
Q186: What is service mesh vs HTTP?
A service mesh often uses HTTP proxying and sidecars to manage traffic, security, and observability between services.
Q187: Why is HTTP observability important?
Because most distributed systems rely on HTTP, and tracing, metrics, and logs need good HTTP context.
Q188: What is request tracing?
Request tracing correlates a single HTTP request across multiple services and components.
Q189: What is correlation ID?
A correlation ID links multiple log entries and spans to the same HTTP request.
Q190: What is the difference between latency and throughput?
Latency measures delay; throughput measures how much data is processed per unit of time.
Q191: What is a performance bottleneck?
A performance bottleneck is the component or resource that limits throughput or increases latency.
Q192: Why does HTTP need good error handling?
Because clients rely on status codes and headers to react correctly to failures and retries.
Q193: What is idempotency in API design?
Idempotency ensures that repeating a request doesn’t create duplicate side effects beyond the first call.
Q194: What is the role of retries in HTTP clients?
Retries help handle transient network issues or service overloads safely.
Q195: What is backoff?
Backoff is a strategy of delaying retries to reduce pressure on failing services.
Q196: Why are timeouts important?
Timeouts prevent clients and servers from hanging indefinitely and causing cascading failures.
Q197: What is cache invalidation?
Cache invalidation removes or refreshes stale entries after content changes.
Q198: What is a stale resource?
A stale resource is a cached item that is older than the latest server version.
Q199: What is last-mile performance?
Last-mile performance refers to the final hop between the network and the user or client system.
Q200: What is the key idea behind HTTP/HTTPS?
HTTP defines how web requests and responses work; HTTPS adds encryption and trust so the web can be used securely and reliably at scale.
Advanced / Expert
Q201: What is HTTP semantics?
HTTP semantics defines the meaning of methods, status codes, headers, and resource representation, independent of transport.
Q202: What is serialization?
Serialization is the conversion of structured data into bytes for transmission, such as JSON or XML.
Q203: What is deserialization?
Deserialization is the reverse process of reading structured data from a byte stream.
Q204: Why is JSON a dominant HTTP API format?
It is lightweight, easy to read, and widely supported across languages and tools.
Q205: What is schema validation?
Schema validation ensures that request or response payloads match the expected structure and constraints.
Q206: What is contract testing?
Contract testing verifies that two systems agree on the HTTP API contract before integration.
Q207: What is API versioning strategy?
Common strategies include URL versioning, header-based versioning, and content negotiation.
Q208: Why is versioning important in HTTP APIs?
Because clients and servers evolve independently and must remain compatible.
Q209: What is a resource-oriented API?
A resource-oriented API exposes domain resources and manipulates them through standard HTTP semantics.
Q210: What is an event-driven API?
An event-driven API pushes updates or notifications, often with SSE or WebSockets instead of polling.
Q211: What is SSE?
SSE (Server-Sent Events) sends HTTP updates from the server to the client over a single long-lived connection.
Q212: What is HTTP long polling?
Long polling keeps an HTTP request open until new data arrives, then closes and reopens.
Q213: What is a streaming response?
A streaming response sends data progressively as it becomes available.
Q214: Why is streaming useful?
Streaming helps handle large data sets, real-time updates, and low-latency APIs.
Q215: What is connection pool saturation?
Connection pool saturation occurs when too many clients compete for limited server connections.
Q216: What is HTTP performance profiling?
Performance profiling analyzes timing, throughput, connection reuse, and bottlenecks across the request lifecycle.
Q217: What is TLS session resumption and why does it matter?
It reduces handshake overhead on repeated connections and improves latency.
Q218: What is forward secrecy?
Forward secrecy means that past session keys remain safe even if long-term keys are later compromised.
Q219: Why is forward secrecy important?
It limits the impact of future key compromise on prior encrypted communications.
Q220: What is ECDHE?
ECDHE is an ephemeral key exchange method commonly used in modern TLS to provide forward secrecy.
Q221: What is mTLS?
mTLS (mutual TLS) verifies both the client and the server certificates during the handshake.
Q222: Why use mTLS?
It offers stronger identity assurance for service-to-service communication.
Q223: What is certificate pinning and what are its trade-offs?
It reduces downgrade and MITM risk but increases operational complexity and can cause outages when keys rotate incorrectly.
Q224: What is HTTP security hardening?
It includes HTTPS only, HSTS, secure cookies, strong TLS, headers like Content-Security-Policy, and trusted certificate chains.
Q225: What is CSP?
CSP (Content Security Policy) restricts script execution and resource loading to reduce XSS risk.
Q226: What is X-Frame-Options?
X-Frame-Options prevents clickjacking by denying or restricting framing of a page.
Q227: What is Referrer-Policy?
Referrer-Policy controls how much referrer information is sent across origins.
Q228: What is Expect-CT?
Expect-CT tells browsers to expect certificate transparency and enforce it for the site.
Q229: What is Content-Security-Policy-Report-Only?
It logs CSP violations without enforcing them, useful for testing changes in production.
Q230: What is HTTP client fingerprinting?
Client fingerprinting uses attributes like User-Agent, TLS configuration, and headers to identify the client.
Q231: What is TLS fingerprinting?
TLS fingerprinting identifies client implementations or versions based on handshake characteristics.
Q232: What is QUIC?
QUIC is a transport protocol designed to reduce latency and improve reliability over the internet.
Q233: Why is HTTP/3 considered better for lossy networks?
Because QUIC handles packet loss more gracefully than TCP-based transports.
Q234: What is 0-RTT in QUIC?
0-RTT allows some requests to start without waiting for a full handshake when a prior connection exists.
Q235: Why is HTTP/3 still not universal?
Because deployment, middlebox compatibility, and maturity vary across infrastructure and clients.
Q236: What is a middlebox?
A middlebox is a network component like a firewall, proxy, or traffic shaper that can alter or block traffic.
Q237: Why do middleboxes matter for HTTP?
They can affect protocol negotiation, performance, security, and compatibility.
Q238: What is protocol downgrading?
Protocol downgrading occurs when a client or server falls back to an older, less secure protocol version.
Q239: How does HSTS mitigate downgrade attacks?
It forces browsers to use HTTPS, preventing insecure fallback to HTTP on new visits.
Q240: What is HTTP Strict Transport Security preloading?
Preloading is where a browser ships a list of HSTS domains to enforce HTTPS before the first request is even made.
Q241: What is a request smuggling attack?
Request smuggling tricks a server or proxy into interpreting a request differently than the backend does.
Q242: What is HTTP desync?
HTTP desync occurs when request or response framing is interpreted inconsistently by components in the chain.
Q243: What is header injection?
Header injection is when untrusted input is used to craft malicious HTTP headers.
Q244: What is response splitting?
Response splitting sends malicious headers or line breaks to cause multiple responses or cache poisoning.
Q245: What is a proxy confusion attack?
A proxy confusion attack causes a proxy or gateway to send a request to the wrong upstream target.
Q246: What is HTTP security testing?
HTTP security testing validates TLS configuration, headers, cookies, auth, and version support.
Q247: Why is secure cookie policy important?
Because stolen or misused cookies can grant access to a user session.
Q248: What is token theft?
Token theft occurs when an API token is leaked, intercepted, or stolen from a client or log.
Q249: What is bearer token leakage?
It is when a bearer token is exposed in logs, URLs, or insecure storage and can be reused by an attacker.
Q250: What is a JWT?
JWT (JSON Web Token) is a compact token format used to represent claims and identity information.
Q251: What are JWT claims?
Claims are key/value pieces of token data, such as sub, exp, scope, or role.
Q252: Why is JWT often used in HTTP APIs?
It is portable, compact, and widely supported across services and clients.
Q253: What is token expiration?
Expiration limits how long a token remains valid before it must be refreshed or reissued.
Q254: What is refresh token rotation?
Refresh token rotation replaces a refresh token after use to reduce theft risk.
Q255: What is OAuth2?
OAuth2 is an authorization framework used to delegate access without exposing user credentials.
Q256: What is OpenID Connect?
OpenID Connect is a layer built on OAuth2 for user authentication and identity claims.
Q257: What is authorization vs authentication?
Authentication answers “who are you?” Authorization answers “what are you allowed to do?”
Q258: What is a signed request?
A signed request includes cryptographic proof of authenticity so the server can verify the sender.
Q259: What is API gateway authorization?
API gateways often validate tokens, enforce policy, and route requests based on identity or roles.
Q260: What is trust boundary in HTTP?
A trust boundary is a transition where identity or security assumptions change, such as from public internet to internal service.
Q261: What is a service-to-service trust model?
It defines how internal services authenticate and authorize each other over HTTP and HTTPS.
Q262: What is mTLS certificate management?
It includes certificate issuance, rotation, deployment, and revocation for service identities.
Q263: What is HTTP observability?
HTTP observability includes logs, metrics, traces, and structured request metadata for diagnosis and monitoring.
Q264: What is APM?
APM (Application Performance Monitoring) tracks HTTP latency, errors, throughput, and dependency health.
Q265: What is distributed tracing over HTTP?
It correlates a user request across multiple services and systems using HTTP metadata and trace propagation headers.
Q266: What are tracing headers?
Tracing headers such as traceparent and baggage propagate context across service boundaries.
Q267: What is a correlation ID in distributed systems?
A correlation ID links related requests and logs across service calls and infrastructure layers.
Q268: Why is HTTP observability important in microservices?
Because the request path is distributed and may span multiple services, networks, and data stores.
Q269: What is a problematic HTTP header for security?
Headers like Authorization, Cookie, and X-Forwarded-For can leak sensitive data if mishandled or logged insecurely.
Q270: What is request normalization?
Request normalization standardizes or transforms incoming HTTP requests before they are processed.
Q271: What is a proxy header attack?
A proxy header attack occurs when untrusted clients set headers such as X-Forwarded-For or Host in a way that bypasses security or routing logic.
Q272: Why should proxy headers be validated?
Because clients can manipulate them if the server trusts them without validation.
Q273: What is absolute URL parsing?
Absolute URL parsing is the conversion of a full URL into host, path, scheme, and port information.
Q274: What is domain fronting?
Domain fronting is a technique that hides the intended backend host behind a trusted CDN host and is often restricted for security reasons.
Q275: What is HTTP/2 prioritization?
HTTP/2 prioritization allows the client to signal which streams are important, improving resource loading.
Q276: What is stream dependency in HTTP/2?
A stream dependency defines which HTTP/2 stream a stream depends on for priority.
Q277: What is HTTP/2 flow control?
Flow control limits how much data one endpoint can send before receiving feedback.
Q278: What is QUIC connection migration?
QUIC allows a connection to continue across network changes, such as IP or port changes.
Q279: What is the main challenge in modern HTTP?
Balancing performance, security, compatibility, and ease of operation across browsers, proxies, and distributed services.
Q280: What is the ultimate goal of HTTP/HTTPS?
To provide a reliable, standardized, secure, and efficient way for systems and users to exchange data across networks and the web.