All categories
Cybersecurity Interview Questions
XSS, CSRF and auth-token attacks: think like an attacker, defend like an engineer.
3 of 3 questions
Topic
Difficulty
Frequency
Round
Type
BeginnerAsked very oftenWeb SecurityConcept round · Concept
How does XSS work, and how do you defend against it?
The browser cannot tell your code from an attacker payload — every XSS defense is about keeping data out of the HTML parser.
xsscspsanitization
IntermediateAsked very oftenAuthenticationConcept round · Concept
Why is storing JWTs in localStorage dangerous?
A JWT is a bearer token: one XSS payload that reads localStorage silently walks away with an account that stays valid until expiry.
jwtlocalstoragehttponly
IntermediateAsked very oftenWeb SecurityConcept round · Concept
How does CSRF work when the attacker cannot read cookies?
The attacker never reads the cookie — the browser volunteers it because cookies follow the destination, not the page that sent you there.
csrfsamesitecookies