🔐

Top 84 Cybersecurity / Web Security Interview Questions & Answers (2026)

84 Questions 45 Beginner 26 Intermediate 13 Advanced

About Cybersecurity / Web Security

This technology is widely used in software development and is a frequent topic in technical interviews at companies of all sizes.

What to Expect in a Cybersecurity / Web Security Interview

Interviews cover both foundational concepts and practical application of this technology, with questions ranging from definitions to architectural decision-making.

How to Use This Guide

Work through questions in order of difficulty to build your understanding progressively. Bookmark challenging questions and revisit them before your interview.

Curated by Tech Baithak Editorial Team  ·  Last updated: May 2026

Beginner 45 questions

Core concepts every Cybersecurity / Web Security developer must know.

01 What is cybersecurity? 02 What is the CIA triad in security? 03 What is a firewall? 04 What is encryption? 05 What is HTTPS and how does it differ from HTTP? 06 What is SQL injection? 07 What is Cross-Site Scripting (XSS)? 08 What is Cross-Site Request Forgery (CSRF)? 09 What is the OWASP Top 10? 10 What is authentication vs authorization? 11 What is multi-factor authentication (MFA)? 12 What is a VPN? 13 What is hashing and how does it differ from encryption? 14 What is a salt in cryptography? 15 What is a DDoS attack? 16 What is a man-in-the-middle (MITM) attack? 17 What is phishing? 18 What is a penetration test? 19 What is social engineering in cybersecurity? 20 What is a zero-day vulnerability? 21 What is the principle of least privilege? 22 What is a SSL/TLS certificate? 23 What is a cookie and how are cookies secured? 24 What is an IDS vs IPS? 25 What is HTTPS Strict Transport Security (HSTS)? 26 What is Content Security Policy (CSP)? 27 What is the difference between symmetric and asymmetric encryption? 28 What is a vulnerability assessment? 29 What is a security misconfiguration? 30 What are HTTP security headers? 31 What is input validation and why is it important? 32 What is broken access control? 33 What is a CVE? 34 What is defense in depth? 35 What is a security audit? 36 What is data encryption at rest and in transit? 37 What is a Security Operations Center (SOC)? 38 What is GDPR and why does it matter for security? 39 What is malware? 40 What is a security patch and why should patches be applied promptly? 41 What is a password policy and what makes a strong password? 42 What is OAuth 2.0? 43 What is JWT (JSON Web Token)? 44 What is two-factor authentication (2FA)? 45 What is network segmentation?
Back to All Topics 84 questions total