HTTP/HTTPS

HTTP/HTTPS


Beginner

Q1: What is HTTP?

HTTP (Hypertext Transfer Protocol) is the protocol used to fetch resources such as HTML pages, images, JSON, and other web content.

Q2: What is HTTPS?

HTTPS is HTTP over TLS/SSL, meaning the HTTP traffic is encrypted and authenticated.

Q3: Why is HTTPS important?

HTTPS protects data in transit from eavesdropping, tampering, and impersonation.

Q4: What is a URL?

A URL (Uniform Resource Locator) is the address used to identify a web resource, such as https://example.com/page.

Q5: What is a URI?

A URI (Uniform Resource Identifier) is a string that identifies a resource, and a URL is a type of URI.

Q6: What is a scheme?

A scheme is the protocol portion of a URL, such as http or https.

Q7: What is a host?

A host is the server name or IP address that receives the request, such as example.com.

Q8: What is a port?

A port is a communication endpoint, such as 80 for HTTP and 443 for HTTPS.

Q9: What is a path?

A path identifies a resource location on the server, such as /products/123.

Q10: What is a query string?

A query string is the part of a URL after ? used to send parameters, such as ?page=2&sort=asc.

Q11: What is a fragment?

A fragment is the part after # and is mainly used by the client for page anchors, such as #section-2.

Q12: What is a client?

A client is the program or browser that sends an HTTP request.

Q13: What is a server?

A server is the program that receives the request and returns a response.

Q14: What is an HTTP request?

An HTTP request is a message sent by the client to the server asking for a resource or action.

Q15: What is an HTTP response?

An HTTP response is the server’s answer to the client’s request.

Q16: What is a status code?

A status code tells the client the result of the request, such as 200 OK or 404 Not Found.

Q17: What is a 200 status code?

200 OK means the request succeeded.

Q18: What is a 201 status code?

201 Created means the request created a new resource.

Q19: What is a 204 status code?

204 No Content means the request succeeded but there is no response body.

Q20: What is a 301 status code?

301 Moved Permanently indicates the resource has permanently moved to another URL.

Q21: What is a 302 status code?

302 Found means the resource is temporarily at a different location.

Q22: What is a 304 status code?

304 Not Modified tells the client the cached version is still valid.

Q23: What is a 400 status code?

400 Bad Request means the request is malformed or invalid.

Q24: What is a 401 status code?

401 Unauthorized means authentication is required.

Q25: What is a 403 status code?

403 Forbidden means the client is authenticated but not allowed to access the resource.

Q26: What is a 404 status code?

404 Not Found means the resource does not exist.

Q27: What is a 405 status code?

405 Method Not Allowed means the HTTP method is not supported for that endpoint.

Q28: What is a 500 status code?

500 Internal Server Error indicates the server encountered an unexpected error.

Q29: What is a 503 status code?

503 Service Unavailable means the server is temporarily unable to handle the request.

Q30: What is HTTP method?

An HTTP method defines the action to perform, such as GET, POST, PUT, DELETE, PATCH.

Q31: What is GET?

GET is used to retrieve a resource without changing the server state.

Q32: What is POST?

POST is used to submit data to create or process a resource.

Q33: What is PUT?

PUT replaces or creates a resource at a known URI.

Q34: What is PATCH?

PATCH applies partial updates to a resource.

Q35: What is DELETE?

DELETE removes a resource.

Q36: What is HEAD?

HEAD requests the headers for a resource without fetching the body.

Q37: What is OPTIONS?

OPTIONS asks the server which methods are allowed for a resource.

Q38: What is TRACE?

TRACE echoes the request back to the client for debugging.

Q39: What is CONNECT?

CONNECT establishes a tunnel, often used by proxies and HTTPS tunneling.

Q40: What is a request header?

A request header contains metadata about the request, such as Host, User-Agent, Accept, and Authorization.

Q41: What is a response header?

A response header contains metadata about the response, such as Content-Type, Server, Cache-Control, and Location.

Q42: What is a request body?

The request body contains data sent to the server, such as JSON, form fields, or file content.

Q43: What is a response body?

The response body contains the actual resource data sent back to the client.

Q44: What is an HTTP header?

An HTTP header is metadata sent as part of a request or response.

Q45: What is Host header?

The Host header tells the server which virtual host is being requested.

Q46: What is User-Agent?

The User-Agent header identifies the client software, such as a browser or API client.

Q47: What is Accept header?

The Accept header tells the server what content types the client supports.

Q48: What is Content-Type?

Content-Type tells the client or server what kind of data is present in the body.

Q49: What is Authorization header?

The Authorization header carries credentials such as tokens or basic auth credentials.

Q50: What is Cookie header?

The Cookie header sends state from the client back to the server.

Q51: What is Set-Cookie?

Set-Cookie is a response header used to create or update a browser cookie.

Q52: What is caching?

Caching stores copies of response data to reduce latency and server load.

Q53: What is Cache-Control?

Cache-Control is a response or request header that controls caching behavior.

Q54: What is ETag?

ETag is a unique identifier for a resource version, used for conditional requests.

Q55: What is If-None-Match?

If-None-Match allows a client to ask the server for the resource only if it has changed.

Q56: What is Last-Modified?

Last-Modified is a header giving the last modification time of a resource.

Q57: What is If-Modified-Since?

If-Modified-Since allows the client to validate cached resources.

Q58: What is a browser cache?

A browser cache stores HTTP responses locally to avoid repeated network requests.

Q59: What is a CDN?

A CDN (Content Delivery Network) caches content closer to users to improve delivery speed.

Q60: What is a reverse proxy?

A reverse proxy sits in front of servers and forwards client requests to backend services.

Q61: What is a forward proxy?

A forward proxy handles requests on behalf of clients, often for filtering or caching.

Q62: What is statelessness in HTTP?

HTTP is stateless, meaning each request is independent and does not inherently retain previous request state.

Q63: Why is HTTP stateless?

Because it is designed to be simple, scalable, and independent across requests.

Q64: What is a session?

A session is a way to maintain state across multiple HTTP requests, usually using cookies or tokens.

Q65: What is a cookie?

A cookie is a small piece of client-side state stored by the browser and sent with future requests.

Q66: Why are cookies used?

Cookies allow the server to remember preferences, login state, and session information.

Q67: What is session management?

Session management is the technique for associating a user or client with a stateful session.

Q68: What is a token?

A token is a credential or identifier used to authenticate or authorize requests, often in headers or cookies.

Q69: What is a bearer token?

A bearer token is a token that grants access to whoever possesses it, so it must be protected.

Q70: What is Basic Auth?

Basic Auth sends a username and password encoded as base64 inside the Authorization header.

Q71: Why is Basic Auth not ideal?

It is not very secure unless used over HTTPS and is weaker than modern token-based auth.

Q72: What is a REST API?

A REST API is a web API that uses HTTP methods and resources to perform operations.

Q73: What is an endpoint?

An endpoint is a URL or path exposed by a service.

Q74: What is API versioning?

API versioning allows multiple versions of an API to coexist as the system evolves.

Q75: What is JSON?

JSON is a common data format used in HTTP request and response bodies.

Q76: What is XML?

XML is another structured document format often used in older APIs.

Q77: What is content negotiation?

Content negotiation lets client and server agree on the best representation format, such as JSON vs XML.

Q78: What is Accept-Encoding?

Accept-Encoding tells the server what compression formats the client supports, such as gzip or br.

Q79: What is gzip?

gzip is a common compression format used to reduce HTTP payload size.

Q80: What is TLS?

TLS (Transport Layer Security) provides encryption, integrity, and authentication for network traffic.

Q81: Why does HTTPS use TLS?

Because it protects HTTP data during transmission.

Q82: What is a certificate?

A certificate is a digitally signed document used to prove identity in TLS.

Q83: What is a certificate authority?

A certificate authority (CA) issues and signs digital certificates.

Q84: What is certificate validation?

Certificate validation confirms that a presented server certificate is trusted and matches the domain.

Q85: What is a self-signed certificate?

A self-signed certificate is signed by itself rather than by a trusted authority.

Q86: What is a certificate chain?

A certificate chain is the sequence of certificates used to establish trust to a root CA.

Q87: What is the TLS handshake?

The TLS handshake is the negotiation that establishes encrypted communication between client and server.

Q88: What is the server name indication?

SNI is an extension that allows a client to specify the hostname it wants to connect to during the TLS handshake.

Q89: Why is SNI important?

It allows multiple HTTPS sites to share the same IP address and certificate selection.

Q90: What is HSTS?

HSTS (HTTP Strict Transport Security) tells browsers to always use HTTPS for a domain.

Q91: Why is HSTS useful?

It prevents downgrade attacks and makes HTTPS enforcement more reliable.

Q92: What is a redirect?

A redirect tells the browser to fetch another URL, usually using 3xx status codes.

Q93: What is a relative URL?

A relative URL is a path relative to the current resource, such as /login.

Q94: What is an absolute URL?

An absolute URL includes the full scheme, host, and path, such as https://example.com/login.

Q95: What is a web browser?

A web browser is a client that renders HTML and makes HTTP requests to web servers.

Q96: What is a web server?

A web server processes HTTP requests and returns resources or data.

Q97: What is a reverse proxy server?

A reverse proxy accepts traffic and forwards it to one or more application servers.

Q98: What is CORS?

CORS (Cross-Origin Resource Sharing) controls which websites can access a resource from another origin.

Q99: What is Same-Origin Policy?

Same-Origin Policy restricts scripts from reading data across origins unless allowed by CORS.

Q100: What is an origin?

An origin is the scheme, host, and port combination, such as https://app.example.com.

Q101: What is a preflight request?

A preflight request is an OPTIONS request sent before a cross-origin request to check allowed methods and headers.

Q102: What is a non-simple request?

A non-simple request is a cross-origin request that uses custom headers, credentials, or non-standard methods.

Q103: What is the role of cookies in CORS?

Cookies are subject to origin restrictions and often require credentials mode to be explicitly enabled.

Q104: Why do browsers enforce CORS?

To protect users and prevent unauthorized cross-site data access.

Q105: What is session fixation?

Session fixation is when an attacker forces a user to use a known session ID to gain unauthorized access.

Q106: Why is HTTPS needed for login flows?

Because credentials and session tokens must not be exposed across the network.

Q107: What is CSRF?

CSRF (Cross-Site Request Forgery) tricks a user’s browser into sending a request to a trusted site.

Q108: What is XSS?

XSS (Cross-Site Scripting) injects malicious scripts into a website or application.

Q109: What is the role of HTTP in XSS?

HTTP alone does not prevent injection; security must be handled in the application and content policies.

Q110: What is a same-site cookie?

A same-site cookie restricts cross-site sending of cookies, reducing CSRF risk.

Q111: What is secure flag on a cookie?

The Secure flag ensures cookies are only sent over HTTPS.

Q112: What is HttpOnly?

HttpOnly prevents JavaScript from reading a cookie, reducing XSS impact.

Q113: What is the difference between HTTP and HTTPS at the socket level?

HTTPS encrypts the transport layer using TLS, while HTTP does not.

Q114: Why is redirecting HTTP to HTTPS important?

It ensures clients consistently use encryption and reduces accidental insecure access.

Q115: What is HTTP/1.1?

HTTP/1.1 is the widely used HTTP version with features like persistent connections and pipelining.

Q116: What is HTTP/2?

HTTP/2 improves performance with multiplexing, binary framing, header compression, and server push.

Q117: What is HTTP/3?

HTTP/3 uses QUIC instead of TCP and offers better multiplexing and lower latency.

Q118: Why is HTTP/2 faster than HTTP/1.1?

It avoids head-of-line blocking and reduces header overhead by multiplexing many streams over one connection.

Q119: What is multiplexing?

Multiplexing allows many requests and responses to share one TCP connection.

Q120: What is header compression?

Header compression reduces the size of repeated HTTP headers to save bandwidth and latency.

Intermediate

Q121: What is a keep-alive connection?

A keep-alive connection reuses the same TCP connection for multiple HTTP requests.

Q122: What is connection reuse?

Connection reuse reduces the overhead of opening new TCP connections for every request.

Q123: What is request pipelining?

Pipelining allows multiple HTTP requests to be sent without waiting for each response, though it is limited in HTTP/1.1.

Q124: What is head-of-line blocking?

Head-of-line blocking occurs when one slow response blocks others in the same connection.

Q125: What is connection coalescing?

Connection coalescing combines multiple network flows or connections to reduce setup costs.

Q126: What is the TCP handshake?

The TCP handshake is the three-step process used before data exchange begins: SYN, SYN-ACK, ACK.

Q127: How does HTTP relate to TCP?

HTTP runs on top of TCP, which provides reliable ordered delivery of bytes.

Q128: Why is HTTPS more expensive than HTTP?

It adds TLS negotiation, certificate validation, and crypto overhead.

Q129: What is a TLS certificate chain validation?

It is the process of validating the server cert through intermediate and root certificates.

Q130: What is OCSP?

OCSP (Online Certificate Status Protocol) checks whether a certificate has been revoked.

Q131: What is OCSP stapling?

OCSP stapling allows the server to provide certificate revocation status during the TLS handshake.

Q132: What is a certificate pinning?

Certificate pinning binds a client to a specific certificate or public key to reduce MITM risk.

Q133: What is certificate rotation?

Certificate rotation is the process of issuing and deploying a new certificate before the old one expires.

Q134: What is a wildcard certificate?

A wildcard certificate covers multiple subdomains under a single domain, such as *.example.com.

Q135: What is a SAN certificate?

A SAN certificate includes multiple subject alternative names, allowing many domains in one cert.

Q136: What is a redirect loop?

A redirect loop happens when a series of redirects repeatedly sends the client back and forth.

Q137: What is a canonical URL?

A canonical URL is the preferred URL for a resource to avoid duplicates and SEO issues.

Q138: What is cache validation?

Cache validation checks whether a cached response is still fresh or stale.

Q139: What is stale-while-revalidate?

It allows a stale resource to be served while an updated copy is revalidated in the background.

Q140: What is stale-if-error?

It allows stale content to be returned when the backend fails.

Q141: What is Vary header?

The Vary header tells caches that the response varies by request headers such as Accept-Encoding or User-Agent.

Q142: What is a conditional request?

A conditional request asks the server to respond only if the resource has changed, saving bandwidth.

Q143: What is a 206 Partial Content response?

206 Partial Content is used when a client requests only part of a resource, such as a range.

Q144: What is Range header?

The Range header asks the server to return a byte range of the resource.

Q145: What is Accept-Language?

Accept-Language tells the server which human language the client prefers.

Q146: What is content encoding?

Content encoding describes how the representation body is encoded, such as gzip.

Q147: What is Transfer-Encoding?

Transfer-Encoding defines how the message body is framed, such as chunked encoding.

Q148: What is chunked transfer encoding?

Chunked encoding splits the body into chunks so the server can stream it without knowing the full size ahead of time.

Q149: What is a payload?

A payload is the data being carried in the request or response body.

Q150: What is a request/response queue?

A queue holds incoming HTTP requests or outgoing responses waiting for processing or delivery.

Q151: What is a load balancer and how does it relate to HTTP?

A load balancer distributes HTTP requests across multiple application instances.

Q152: Why does HTTP need compression?

Compression reduces payload size, improving latency and bandwidth consumption.

Q153: What is HTTP/2 server push?

Server push sends resources proactively to the client before it asks for them.

Q154: Why is server push controversial?

It can waste bandwidth if the client never uses the pushed assets.

Q155: What is a character set?

A character set defines how text bytes are mapped to characters, such as UTF-8.

Q156: What is Content-Language?

Content-Language tells the client which language the content is written in.

Q157: What is a web API contract?

A web API contract defines the expected endpoints, data formats, methods, and status codes.

Q158: What is an idempotent request?

An idempotent request produces the same result when repeated, such as GET or DELETE in many patterns.

Q159: What is a safe method?

A safe method is one that does not modify server state, such as GET and HEAD.

Q160: What is a non-idempotent method?

A non-idempotent method may have side effects, such as POST or PATCH.

Q161: What is rate limiting?

Rate limiting restricts how often a client can call an API or endpoint.

Q162: Why is rate limiting important?

It prevents abuse, service degradation, and resource exhaustion.

Q163: What is retry-after?

Retry-After tells clients how long to wait before retrying a request after a server-side condition.

Q164: What is concurrency in HTTP?

Concurrency refers to multiple requests being processed at the same time by the client or server.

Q165: What is long polling?

Long polling keeps a request open until new data becomes available, then returns it.

Q166: What is WebSocket?

WebSocket is a protocol that provides continuous bidirectional communication with a persistent TCP socket.

Q167: Why is WebSocket different from HTTP?

HTTP is request/response-based; WebSocket is full-duplex and stateful.

Q168: What is HTTP upgrade?

HTTP upgrade allows a client to switch protocols, such as from HTTP to WebSocket.

Q169: What is a proxy protocol?

A proxy protocol adds metadata about the original client connection to requests forwarded through a proxy.

Q170: What is a connection limit?

A connection limit defines how many simultaneous connections a server or load balancer will handle.

Q171: What is certificate transparency?

Certificate transparency logs public certificates so browsers and clients can detect malicious or unintended issuance.

Q172: What is OCSP responder?

An OCSP responder answers certificate revocation checks for certificate validation.

Q173: What is H2C?

H2C is HTTP/2 without TLS, used in trusted internal environments.

Q174: What is HTTP/3 over QUIC?

HTTP/3 uses QUIC to reduce connection setup latency and improve recovery under packet loss.

Q175: What is the difference between TLS and HTTPS?

TLS is the encryption mechanism; HTTPS is HTTP transported using TLS.

Q176: What is a TLS session resumption?

Session resumption reuses a previous TLS handshake state to reduce handshake overhead.

Q177: What is a proof of domain ownership?

A proof of domain ownership is a mechanism used during certificate issuance to confirm the requester controls the domain.

Q178: What is TLS ALPN?

ALPN (Application-Layer Protocol Negotiation) allows a TLS client and server to negotiate protocol versions such as HTTP/1.1, HTTP/2, or HTTP/3.

Q179: What is CDN edge logic?

CDN edge logic decides how to route, cache, or rewrite requests close to users.

Q180: What is an origin server?

An origin server is the original source server for the content, behind caches and proxies.

Q181: What is an API gateway?

An API gateway is a layer that handles routing, authentication, rate limiting, and transformation of API traffic.

Q182: Why is HTTP important in microservices?

Microservices communicate over HTTP or HTTPS for modularity, interoperability, and standardization.

Q183: What is a health check endpoint?

A health check endpoint confirms whether a service is running and ready to receive requests.

Q184: What is a readiness endpoint?

A readiness endpoint tells a load balancer or orchestrator whether the service is ready to receive traffic.

Q185: What is a liveness endpoint?

A liveness endpoint tells whether an application is alive and not stuck or deadlocked.

Q186: What is service mesh vs HTTP?

A service mesh often uses HTTP proxying and sidecars to manage traffic, security, and observability between services.

Q187: Why is HTTP observability important?

Because most distributed systems rely on HTTP, and tracing, metrics, and logs need good HTTP context.

Q188: What is request tracing?

Request tracing correlates a single HTTP request across multiple services and components.

Q189: What is correlation ID?

A correlation ID links multiple log entries and spans to the same HTTP request.

Q190: What is the difference between latency and throughput?

Latency measures delay; throughput measures how much data is processed per unit of time.

Q191: What is a performance bottleneck?

A performance bottleneck is the component or resource that limits throughput or increases latency.

Q192: Why does HTTP need good error handling?

Because clients rely on status codes and headers to react correctly to failures and retries.

Q193: What is idempotency in API design?

Idempotency ensures that repeating a request doesn’t create duplicate side effects beyond the first call.

Q194: What is the role of retries in HTTP clients?

Retries help handle transient network issues or service overloads safely.

Q195: What is backoff?

Backoff is a strategy of delaying retries to reduce pressure on failing services.

Q196: Why are timeouts important?

Timeouts prevent clients and servers from hanging indefinitely and causing cascading failures.

Q197: What is cache invalidation?

Cache invalidation removes or refreshes stale entries after content changes.

Q198: What is a stale resource?

A stale resource is a cached item that is older than the latest server version.

Q199: What is last-mile performance?

Last-mile performance refers to the final hop between the network and the user or client system.

Q200: What is the key idea behind HTTP/HTTPS?

HTTP defines how web requests and responses work; HTTPS adds encryption and trust so the web can be used securely and reliably at scale.

Advanced / Expert

Q201: What is HTTP semantics?

HTTP semantics defines the meaning of methods, status codes, headers, and resource representation, independent of transport.

Q202: What is serialization?

Serialization is the conversion of structured data into bytes for transmission, such as JSON or XML.

Q203: What is deserialization?

Deserialization is the reverse process of reading structured data from a byte stream.

Q204: Why is JSON a dominant HTTP API format?

It is lightweight, easy to read, and widely supported across languages and tools.

Q205: What is schema validation?

Schema validation ensures that request or response payloads match the expected structure and constraints.

Q206: What is contract testing?

Contract testing verifies that two systems agree on the HTTP API contract before integration.

Q207: What is API versioning strategy?

Common strategies include URL versioning, header-based versioning, and content negotiation.

Q208: Why is versioning important in HTTP APIs?

Because clients and servers evolve independently and must remain compatible.

Q209: What is a resource-oriented API?

A resource-oriented API exposes domain resources and manipulates them through standard HTTP semantics.

Q210: What is an event-driven API?

An event-driven API pushes updates or notifications, often with SSE or WebSockets instead of polling.

Q211: What is SSE?

SSE (Server-Sent Events) sends HTTP updates from the server to the client over a single long-lived connection.

Q212: What is HTTP long polling?

Long polling keeps an HTTP request open until new data arrives, then closes and reopens.

Q213: What is a streaming response?

A streaming response sends data progressively as it becomes available.

Q214: Why is streaming useful?

Streaming helps handle large data sets, real-time updates, and low-latency APIs.

Q215: What is connection pool saturation?

Connection pool saturation occurs when too many clients compete for limited server connections.

Q216: What is HTTP performance profiling?

Performance profiling analyzes timing, throughput, connection reuse, and bottlenecks across the request lifecycle.

Q217: What is TLS session resumption and why does it matter?

It reduces handshake overhead on repeated connections and improves latency.

Q218: What is forward secrecy?

Forward secrecy means that past session keys remain safe even if long-term keys are later compromised.

Q219: Why is forward secrecy important?

It limits the impact of future key compromise on prior encrypted communications.

Q220: What is ECDHE?

ECDHE is an ephemeral key exchange method commonly used in modern TLS to provide forward secrecy.

Q221: What is mTLS?

mTLS (mutual TLS) verifies both the client and the server certificates during the handshake.

Q222: Why use mTLS?

It offers stronger identity assurance for service-to-service communication.

Q223: What is certificate pinning and what are its trade-offs?

It reduces downgrade and MITM risk but increases operational complexity and can cause outages when keys rotate incorrectly.

Q224: What is HTTP security hardening?

It includes HTTPS only, HSTS, secure cookies, strong TLS, headers like Content-Security-Policy, and trusted certificate chains.

Q225: What is CSP?

CSP (Content Security Policy) restricts script execution and resource loading to reduce XSS risk.

Q226: What is X-Frame-Options?

X-Frame-Options prevents clickjacking by denying or restricting framing of a page.

Q227: What is Referrer-Policy?

Referrer-Policy controls how much referrer information is sent across origins.

Q228: What is Expect-CT?

Expect-CT tells browsers to expect certificate transparency and enforce it for the site.

Q229: What is Content-Security-Policy-Report-Only?

It logs CSP violations without enforcing them, useful for testing changes in production.

Q230: What is HTTP client fingerprinting?

Client fingerprinting uses attributes like User-Agent, TLS configuration, and headers to identify the client.

Q231: What is TLS fingerprinting?

TLS fingerprinting identifies client implementations or versions based on handshake characteristics.

Q232: What is QUIC?

QUIC is a transport protocol designed to reduce latency and improve reliability over the internet.

Q233: Why is HTTP/3 considered better for lossy networks?

Because QUIC handles packet loss more gracefully than TCP-based transports.

Q234: What is 0-RTT in QUIC?

0-RTT allows some requests to start without waiting for a full handshake when a prior connection exists.

Q235: Why is HTTP/3 still not universal?

Because deployment, middlebox compatibility, and maturity vary across infrastructure and clients.

Q236: What is a middlebox?

A middlebox is a network component like a firewall, proxy, or traffic shaper that can alter or block traffic.

Q237: Why do middleboxes matter for HTTP?

They can affect protocol negotiation, performance, security, and compatibility.

Q238: What is protocol downgrading?

Protocol downgrading occurs when a client or server falls back to an older, less secure protocol version.

Q239: How does HSTS mitigate downgrade attacks?

It forces browsers to use HTTPS, preventing insecure fallback to HTTP on new visits.

Q240: What is HTTP Strict Transport Security preloading?

Preloading is where a browser ships a list of HSTS domains to enforce HTTPS before the first request is even made.

Q241: What is a request smuggling attack?

Request smuggling tricks a server or proxy into interpreting a request differently than the backend does.

Q242: What is HTTP desync?

HTTP desync occurs when request or response framing is interpreted inconsistently by components in the chain.

Q243: What is header injection?

Header injection is when untrusted input is used to craft malicious HTTP headers.

Q244: What is response splitting?

Response splitting sends malicious headers or line breaks to cause multiple responses or cache poisoning.

Q245: What is a proxy confusion attack?

A proxy confusion attack causes a proxy or gateway to send a request to the wrong upstream target.

Q246: What is HTTP security testing?

HTTP security testing validates TLS configuration, headers, cookies, auth, and version support.

Q247: Why is secure cookie policy important?

Because stolen or misused cookies can grant access to a user session.

Q248: What is token theft?

Token theft occurs when an API token is leaked, intercepted, or stolen from a client or log.

Q249: What is bearer token leakage?

It is when a bearer token is exposed in logs, URLs, or insecure storage and can be reused by an attacker.

Q250: What is a JWT?

JWT (JSON Web Token) is a compact token format used to represent claims and identity information.

Q251: What are JWT claims?

Claims are key/value pieces of token data, such as sub, exp, scope, or role.

Q252: Why is JWT often used in HTTP APIs?

It is portable, compact, and widely supported across services and clients.

Q253: What is token expiration?

Expiration limits how long a token remains valid before it must be refreshed or reissued.

Q254: What is refresh token rotation?

Refresh token rotation replaces a refresh token after use to reduce theft risk.

Q255: What is OAuth2?

OAuth2 is an authorization framework used to delegate access without exposing user credentials.

Q256: What is OpenID Connect?

OpenID Connect is a layer built on OAuth2 for user authentication and identity claims.

Q257: What is authorization vs authentication?

Authentication answers “who are you?” Authorization answers “what are you allowed to do?”

Q258: What is a signed request?

A signed request includes cryptographic proof of authenticity so the server can verify the sender.

Q259: What is API gateway authorization?

API gateways often validate tokens, enforce policy, and route requests based on identity or roles.

Q260: What is trust boundary in HTTP?

A trust boundary is a transition where identity or security assumptions change, such as from public internet to internal service.

Q261: What is a service-to-service trust model?

It defines how internal services authenticate and authorize each other over HTTP and HTTPS.

Q262: What is mTLS certificate management?

It includes certificate issuance, rotation, deployment, and revocation for service identities.

Q263: What is HTTP observability?

HTTP observability includes logs, metrics, traces, and structured request metadata for diagnosis and monitoring.

Q264: What is APM?

APM (Application Performance Monitoring) tracks HTTP latency, errors, throughput, and dependency health.

Q265: What is distributed tracing over HTTP?

It correlates a user request across multiple services and systems using HTTP metadata and trace propagation headers.

Q266: What are tracing headers?

Tracing headers such as traceparent and baggage propagate context across service boundaries.

Q267: What is a correlation ID in distributed systems?

A correlation ID links related requests and logs across service calls and infrastructure layers.

Q268: Why is HTTP observability important in microservices?

Because the request path is distributed and may span multiple services, networks, and data stores.

Q269: What is a problematic HTTP header for security?

Headers like Authorization, Cookie, and X-Forwarded-For can leak sensitive data if mishandled or logged insecurely.

Q270: What is request normalization?

Request normalization standardizes or transforms incoming HTTP requests before they are processed.

Q271: What is a proxy header attack?

A proxy header attack occurs when untrusted clients set headers such as X-Forwarded-For or Host in a way that bypasses security or routing logic.

Q272: Why should proxy headers be validated?

Because clients can manipulate them if the server trusts them without validation.

Q273: What is absolute URL parsing?

Absolute URL parsing is the conversion of a full URL into host, path, scheme, and port information.

Q274: What is domain fronting?

Domain fronting is a technique that hides the intended backend host behind a trusted CDN host and is often restricted for security reasons.

Q275: What is HTTP/2 prioritization?

HTTP/2 prioritization allows the client to signal which streams are important, improving resource loading.

Q276: What is stream dependency in HTTP/2?

A stream dependency defines which HTTP/2 stream a stream depends on for priority.

Q277: What is HTTP/2 flow control?

Flow control limits how much data one endpoint can send before receiving feedback.

Q278: What is QUIC connection migration?

QUIC allows a connection to continue across network changes, such as IP or port changes.

Q279: What is the main challenge in modern HTTP?

Balancing performance, security, compatibility, and ease of operation across browsers, proxies, and distributed services.

Q280: What is the ultimate goal of HTTP/HTTPS?

To provide a reliable, standardized, secure, and efficient way for systems and users to exchange data across networks and the web.