18 cards · Foundations, Practitioner, Applied, Advanced, Expert
Web AppSec interview questions and practice topics
Web application security: injection, cross-site scripting, broken access control, SSRF, authentication and session flaws, and the OWASP Top 10. These are the questions AppSec, pentest and product-security interviews return to most.
Each card is a topic to explain out loud against the clock: 9 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick Web AppSec as a focus.
L1 Foundations What it is
L2 Practitioner How it works
- Cross-Site Request ForgeryWhat is CSRF, and why do SameSite cookies change the picture?Explain · Interview
- Cross-Site Scripting (XSS)Explain the difference between stored, reflected and DOM-based XSS, and what actually stops each one.Explain · Interview · Deep dive
- Login Spike from 4,000 IPsHow do you tell credential stuffing from a brute-force attack, and how do you respond?Incident · Interview
- Prioritising the OWASP Top 10Explain · Deep dive
L3 Applied Abuse and defence in real systems
- CORS MisconfigurationExplain
- Insecure DeserializationExplain
- JWT PitfallsWhat are the most common ways JWT-based authentication goes wrong?Explain · Interview
- Metadata Hits from the PDF ServiceYou get this alert on call. What do you do in the first hour?Incident · Interview
- Server-Side Request ForgeryExplain SSRF and why it is so dangerous in cloud environments.Explain · Interview · Deep dive
- Support Ticket Steals Admin SessionIncident
- Web Shell in Uploads FolderIncident
L4 Advanced Edge cases, bypasses, trade-offs
L5 Expert Research-grade, architecture-level
Other domains
Network · Identity & AD · Cloud · Cryptography · Blue team / DFIR · Malware & intel · Famous breaches · GRC · AI security