Spring Security
Spring Security
Beginner
Q1: What is Spring Security?
Spring Security is a framework for authentication, authorization, and protection against common attacks in Spring applications.
Q2: Why use Spring Security?
It provides robust, configurable security with secure defaults and deep Spring integration.
Q3: Authentication vs Authorization?
Authentication verifies identity; authorization determines allowed actions.
Q4: What is a principal?
The currently authenticated user/system identity.
Q5: What is GrantedAuthority?
A permission/role representation attached to authenticated principal.
Q6: What is SecurityContext?
Holds authentication information for current execution context.
Q7: What is SecurityContextHolder?
Utility class providing access to SecurityContext (thread-bound by default).
Q8: What is Authentication object?
Represents authentication request or authenticated principal token.
Q9: What is UserDetails?
Core interface describing user credentials and authorities.
Q10: What is UserDetailsService?
Service loading UserDetails by username (or identifier).
Q11: What is PasswordEncoder?
Strategy for hashing/verifying passwords.
Q12: Why not store plain-text passwords?
If leaked, plain-text passwords immediately compromise all accounts.
Q13: Recommended password encoder in Spring Security?
BCrypt is commonly recommended for password hashing.
Q14: What is BCrypt?
Adaptive one-way password hashing algorithm with configurable strength.
Q15: What is AuthenticationManager?
Main API that authenticates Authentication requests.
Q16: What is AuthenticationProvider?
Component that performs actual authentication logic for specific mechanism.
Q17: What is DaoAuthenticationProvider?
Provider using UserDetailsService + PasswordEncoder for username/password auth.
Q18: What is SecurityFilterChain?
Defines ordered security filters and HTTP authorization rules.
Q19: Why is filter order important?
Security behavior depends on correct sequence of authentication/authorization filters.
Q20: What is UsernamePasswordAuthenticationFilter?
Processes username/password login submissions.
Q21: What is Basic Authentication?
HTTP auth scheme sending credentials in Authorization header (use only with TLS).
Q22: What is form login?
Browser-oriented authentication via HTML login page and session.
Q23: What is HttpSecurity?
Fluent API for configuring web security rules.
Q24: What is csrf() in Spring Security?
Configures CSRF protection settings.
Q25: What is CSRF?
Attack forcing authenticated browser to send unintended state-changing requests.
Q26: Is CSRF protection needed for stateless JWT APIs?
Often disabled for pure stateless APIs not using browser cookies for auth (context-dependent).
Q27: What is CORS?
Browser security model controlling cross-origin requests.
Q28: CORS vs CSRF?
CORS controls origin access; CSRF protects against forged authenticated actions.
Q29: What is session-based authentication?
Server stores auth state in HTTP session after login.
Q30: What is stateless authentication?
Each request carries credentials/token; server does not store session auth state.
Q31: What is JWT?
JSON Web Token carrying signed claims for stateless auth.
Q32: Is JWT encrypted by default?
No, standard JWS tokens are signed, not encrypted.
Q33: What is role in Spring Security?
Authority convention often prefixed with ROLE_.
Q34: hasRole vs hasAuthority?
hasRole("ADMIN") checks ROLE_ADMIN; hasAuthority checks exact authority string.
Q35: What is permitAll()?
Allows unrestricted access to matched endpoints.
Q36: What is authenticated()?
Requires any authenticated user.
Q37: What is denyAll()?
Blocks all access to matched endpoints.
Q38: What is anonymous() access?
Allows only unauthenticated users (framework anonymous principal context).
Q39: What is logout support?
Invalidates auth/session and clears context/cookies as configured.
Q40: What is remember-me?
Mechanism to persist login across browser restarts using secure tokens/cookies.
Q41: Should remember-me be used for high-risk apps?
Use cautiously with strict controls or avoid for sensitive domains.
Q42: What is default login page behavior?
Spring Security can generate one automatically if form login enabled.
Q43: What is entry point in security?
Component starting authentication flow when unauthenticated access occurs.
Q44: What is AccessDeniedHandler?
Handles 403 Forbidden when authenticated user lacks permissions.
Q45: What is AuthenticationEntryPoint?
Handles 401-like responses or auth initiation for unauthenticated requests.
Q46: What is method security?
Applying authorization rules at method level.
Q47: Common method security annotations?
@PreAuthorize, @PostAuthorize, @Secured, @RolesAllowed.
Q48: How enable method security?
Use annotation-based configuration (e.g., @EnableMethodSecurity).
Q49: What is @PreAuthorize?
Evaluates expression before method execution.
Q50: What is @PostAuthorize?
Evaluates authorization after method returns.
Q51: Why prefer least privilege?
Minimizes blast radius of compromised accounts.
Q52: What is security by default mindset?
Start restrictive, explicitly open only required endpoints/actions.
Q53: What is common beginner Spring Security mistake?
Permitting broad paths accidentally (e.g., overly wide matchers).
Q54: Another beginner mistake?
Disabling CSRF/CORS without understanding threat model.
Q55: Why always use HTTPS with authentication?
Protects credentials/tokens from interception.
Q56: What is secure cookie flag?
Ensures cookies sent only over HTTPS.
Q57: What is HttpOnly cookie flag?
Prevents JavaScript access to cookie values.
Q58: What is SameSite cookie attribute?
Helps mitigate cross-site request behaviors.
Q59: Beginner API security baseline?
HTTPS, strong password hashing, narrow authorization rules, validated tokens.
Q60: Beginner best practice?
Use framework defaults first, then customize with explicit threat-driven decisions.
Intermediate
Q61: What is request matcher in Spring Security?
Rule that selects which requests a security rule/filter chain applies to.
Q62: Why can multiple SecurityFilterChain beans be useful?
Different security rules for different endpoint groups (e.g., API vs actuator).
Q63: How does chain selection work conceptually?
First matching chain handles request (ordering matters).
Q64: What is custom authentication filter?
User-defined filter extracting credentials/tokens and creating Authentication requests.
Q65: Where place JWT filter usually?
Before username/password auth filter (exact placement depends on design).
Q66: What is OncePerRequestFilter?
Convenience base filter ensuring single execution per request dispatch path.
Q67: What is SecurityContext persistence behavior?
Context loaded/saved per request depending on session/stateless configuration.
Q68: What is SessionCreationPolicy?
Controls whether security creates/uses HTTP sessions.
Q69: SessionCreationPolicy.STATELESS meaning?
Do not create/use HTTP session for SecurityContext.
Q70: What is request cache in Spring Security?
Stores original request for post-login redirection in browser flows.
Q71: Should request cache be used in stateless APIs?
Usually disabled for pure API use cases.
Q72: What is CSRF token repository?
Storage strategy for CSRF tokens (session/cookie-based variants).
Q73: What is CookieCsrfTokenRepository?
Stores CSRF token in cookie (commonly for browser clients).
Q74: What is CORS preflight request?
OPTIONS request browser sends to validate cross-origin permissions.
Q75: Why must security allow proper preflight handling?
Blocked preflight prevents legitimate browser API calls.
Q76: What is exceptionHandling() config used for?
Customize entry points and access denied behavior.
Q77: What is custom AuthenticationProvider use case?
Integrate LDAP, external IDP, OTP, or domain-specific credential checks.
Q78: What is account status checks in authentication?
Validate locked/disabled/expired accounts before success.
Q79: What is brute-force mitigation pattern?
Rate limits, lockouts/backoff, CAPTCHA/risk signals.
Q80: What is MFA (multi-factor authentication)?
Requiring additional verification factors beyond password.
Q81: Can Spring Security support MFA flows?
Yes, via custom/auth provider orchestration and external identity integrations.
Q82: What is password upgrade encoding?
Re-encode old hashes with stronger settings at login.
Q83: What is DelegatingPasswordEncoder?
Supports multiple hash formats and gradual migration.
Q84: What is authority mapping?
Transforming external claims/roles into internal GrantedAuthorities.
Q85: What is role hierarchy?
Defines implied roles (e.g., ADMIN implies USER).
Q86: What is SpEL in method security?
Expression language evaluating authorization rules dynamically.
Q87: Example method security expression?
@PreAuthorize("hasRole('ADMIN') or #id = authentication.name")=
Q88: What is @AuthenticationPrincipal?
Injects current principal into controller method parameter.
Q89: What is security context propagation issue?
Auth context may be lost across async threads if not propagated.
Q90: How propagate security context in async tasks?
Use delegating executors/wrappers designed for security context transfer.
Q91: What is ACL in Spring Security concept?
Fine-grained object-level permission model (advanced use case).
Q92: Why ACLs can be complex?
High rule cardinality and performance/management overhead.
Q93: What is OAuth2?
Authorization framework allowing delegated access via tokens.
Q94: What is OpenID Connect (OIDC)?
Identity layer on top of OAuth2 providing authentication and user identity claims.
Q95: OAuth2 roles: Resource Owner, Client, Authorization Server, Resource Server?
Core actors in delegated authorization flow.
Q96: What is authorization code flow?
Server-side exchange of auth code for tokens, common for web apps.
Q97: What is client credentials flow?
Machine-to-machine flow without end-user login.
Q98: What is refresh token?
Longer-lived credential used to obtain new access tokens.
Q99: What is token introspection?
Runtime validation of opaque token with authorization server.
Q100: JWT validation essentials?
Signature verification, issuer/audience checks, expiration/not-before checks.
Q101: Why validate audience claim?
Ensures token is intended for your API/resource.
Q102: Why validate issuer claim?
Ensures token comes from trusted authority.
Q103: What is key rotation in JWT systems?
Changing signing keys periodically while maintaining validation continuity.
Q104: What is JWK set endpoint?
Endpoint publishing public keys used to verify JWT signatures.
Q105: What is resource server in Spring Security?
Component validating bearer tokens for protected APIs.
Q106: What is OAuth2 client in Spring Security?
App acting as OAuth2 client for login or delegated calls.
Q107: What is scope-based authorization?
Granting permissions based on token scopes (e.g., read:orders).
Q108: Role vs scope?
Roles are app/domain-centric; scopes are OAuth delegated permission strings.
Q109: What is opaque token?
Token without self-contained claims requiring introspection.
Q110: JWT vs opaque token tradeoff?
JWT enables local validation; opaque can simplify revocation/control centrally.
Q111: What is token revocation challenge with JWT?
Stateless tokens remain valid until expiry unless additional revocation strategy used.
Q112: Revocation mitigation options?
Short TTL, deny-lists, token versioning, introspection-based checks.
Q113: What is security headers support?
Automatic HTTP headers for browser hardening (HSTS, X-Content-Type-Options, etc.).
Q114: Why configure Content Security Policy (CSP)?
Mitigates XSS by restricting script/resource sources.
Q115: What is clickjacking defense header?
X-Frame-Options or CSP frame-ancestors directives.
Q116: What is HSTS?
Forces HTTPS usage via Strict-Transport-Security header.
Q117: What is intermediate anti-pattern in Spring Security?
Stuffing business authorization logic directly into controllers.
Q118: Better pattern for authorization logic?
Method/domain-level policies with clear reusable authorization services.
Q119: Why separate authentication and domain authorization concerns?
Improves maintainability, clarity, and auditability.
Q120: What is secure password reset baseline?
Single-use short-lived tokens + strong verification + audit logging.
Q121: What is account enumeration risk?
Leaking whether account exists via error messages/timing.
Q122: How reduce enumeration risk?
Generic responses and consistent processing paths.
Q123: What is intermediate testing focus for security?
Endpoint authorization matrix, method security, token validation, failure paths.
Q124: What tool style for security integration tests?
MockMvc/WebTestClient with authenticated/unauthenticated scenarios.
Q125: Why test negative paths heavily?
Security failures usually emerge in denied/invalid/edge conditions.
Q126: What is intermediate observability need?
Audit auth events, denied access, anomaly rates, token failures.
Q127: What must never be logged?
Raw passwords, secrets, private keys, full sensitive tokens.
Q128: What is token redaction logging practice?
Log minimal token fingerprint/claims, never full bearer token.
Q129: Intermediate maturity signal?
Team can explain every permit rule and authentication path in production.
Q130: Intermediate best practice?
Threat-model-driven configuration with least privilege and strong tests.
Advanced
Q131: What is zero-trust mindset for Spring services?
Authenticate/authorize every request and avoid implicit network trust.
Q132: What is defense in depth in Spring Security?
Layered controls: gateway, app security, method rules, data policies, auditing.
Q133: What is policy decision vs enforcement separation?
Central policy logic with distributed enforcement points.
Q134: What is ABAC?
Attribute-based access control using subject/resource/context attributes.
Q135: RBAC vs ABAC tradeoff?
RBAC simpler; ABAC more expressive but more complex to govern.
Q136: What is fine-grained authorization architecture?
Domain permission checks near business operations, not only URL-level.
Q137: What is confused deputy problem in microservices?
Service misuses higher privilege on behalf of less privileged caller.
Q138: Mitigation for confused deputy?
Propagate caller identity/claims and enforce downstream authorization.
Q139: What is token exchange concept?
Exchanging one token for another scoped token for downstream service.
Q140: Why use short-lived access tokens?
Limits exposure window if token is leaked.
Q141: What is secure key management requirement?
Protect signing keys in HSM/KMS and rotate with auditable process.
Q142: What is asymmetric vs symmetric signing tradeoff?
Asymmetric improves key distribution separation; symmetric simpler but riskier sharing.
Q143: What is mTLS role with Spring Security ecosystems?
Mutual TLS provides strong service identity at transport layer.
Q144: Is mTLS a replacement for app authorization?
No, it complements but does not replace fine-grained authZ logic.
Q145: What is step-up authentication?
Require stronger auth factors for sensitive operations.
Q146: What is risk-based authentication?
Adaptive controls based on context/anomaly signals.
Q147: What is session fixation protection?
Changing session id after authentication to prevent hijacking.
Q148: What is concurrent session control?
Limit active sessions per user/account.
Q149: What is logout propagation challenge in distributed systems?
Revoking access across many services/tokens consistently.
Q150: What is back-channel logout concept?
Server-to-server logout notification to relying parties.
Q151: What is authorization cache pitfall?
Stale permissions after role/policy changes.
Q152: How manage permission cache safely?
Short TTL, event-driven invalidation, versioned policies.
Q153: What is method security performance concern?
Excessive per-call SpEL/policy checks on hot paths.
Q154: Optimization strategy for authorization checks?
Cache stable decisions carefully and move complex checks to dedicated policy services.
Q155: What is audit log integrity requirement?
Tamper-evident, append-only, restricted access, retention policy alignment.
Q156: What regulations often affect security logging?
Industry/location-specific compliance requirements (e.g., finance/health/privacy laws).
Q157: What is incident response readiness in security design?
Actionable logs, alerting, runbooks, token/key revocation procedures.
Q158: What is security chaos testing?
Inject auth failures/key rotation issues to validate resilience.
Q159: What is fail-open vs fail-closed in auth systems?
Fail-closed denies on uncertainty; fail-open allows continuity with risk.
Q160: Which components should usually fail-closed?
Authentication/authorization decision points for protected resources.
Q161: What is side-channel leakage in auth endpoints?
Timing/error differences revealing credential/account information.
Q162: How reduce timing side channels?
Constant-time comparisons and normalized error processing.
Q163: What is password pepper concept?
Server-side secret combined with password hashing for extra protection.
Q164: What is secrets rotation policy?
Regularly rotate credentials/keys with tested rollback and dual-key windows.
Q165: What is machine identity management?
Secure issuance/rotation of service credentials/certificates.
Q166: What is SPIFFE/SPIRE relevance conceptually?
Standardized workload identities for zero-trust environments.
Q167: What is gateway vs app auth boundary strategy?
Gateway handles coarse controls; app enforces domain/resource-level authorization.
Q168: What is BFF security benefit?
Tailored token handling and reduced exposure for browser/mobile clients.
Q169: What is token binding/DPoP concept?
Binding token use to proof-of-possession key to reduce replay risk.
Q170: What is replay attack mitigation for APIs?
Nonce/timestamps, short TTL tokens, PoP mechanisms, idempotency controls.
Q171: What is advanced CSRF nuance with SameSite?
SameSite helps but may not replace CSRF tokens in all browser/workflow cases.
Q172: What is secure defaults governance?
Org-level baseline configs/starters preventing insecure deviations.
Q173: What is biggest advanced Spring Security anti-pattern?
Over-permissive wildcard rules added “temporarily” and never removed.
Q174: What is migration strategy for legacy security configs?
Incremental hardening with automated authorization tests and telemetry.
Q175: What is production readiness checklist core?
TLS, strong auth, least privilege, auditing, rotation, alerting, recovery drills.
Q176: What is long-term maintainability principle?
Keep policies explicit, versioned, reviewed, and test-enforced.
Q177: What is mature team behavior in Spring Security?
They can explain every access rule, token trust boundary, and failure mode.
Q178: What is final architecture principle?
Treat security as product architecture, not middleware checkbox.
Q179: What is final operations principle?
Continuously monitor, test, and rotate—security posture is never static.
Q180: Final maturity principle?
Secure-by-default, least-privilege, observable, and resilient under attack/failure.