Open cardosec

18 cards · Foundations, Practitioner, Applied, Advanced, Expert

Web AppSec interview questions and practice topics

Web application security: injection, cross-site scripting, broken access control, SSRF, authentication and session flaws, and the OWASP Top 10. These are the questions AppSec, pentest and product-security interviews return to most.

Each card is a topic to explain out loud against the clock: 9 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick Web AppSec as a focus.

L1 Foundations What it is

L2 Practitioner How it works

L3 Applied Abuse and defence in real systems

L4 Advanced Edge cases, bypasses, trade-offs

L5 Expert Research-grade, architecture-level

Other domains

Network · Identity & AD · Cloud · Cryptography · Blue team / DFIR · Malware & intel · Famous breaches · GRC · AI security