Scenario-Based Security Interview Questions and Answers
Top 10 real-world security scenario interview questions with Mermaid diagrams, production architectures, troubleshooting approaches, and Solution Architect best practices.
Scenario-Based Security Interview Questions & Answers
Senior Java Developers, Technical Leads, and Solution Architects are frequently asked real-world security scenarios instead of theoretical questions.
The interviewer wants to evaluate:
- Problem-solving ability
- Security architecture knowledge
- Production troubleshooting
- Risk analysis
- Decision making
- Enterprise best practices
Scenario 1. Your REST APIs are publicly exposed. How would you secure them?
Answer
I would implement multiple security layers instead of depending only on authentication.
Production Architecture
flowchart TD
Client --> HTTPS
HTTPS --> WAF
WAF --> ApiGateway["API Gateway"]
ApiGateway["API Gateway"] --> OAuth2/OIDC
OAuth2/OIDC --> JwtValidation["JWT Validation"]
JwtValidation["JWT Validation"] --> RateLimiter["Rate Limiter"]
RateLimiter["Rate Limiter"] --> SpringSecurity["Spring Security"]
SpringSecurity["Spring Security"] --> BusinessService["Business Service"]
BusinessService["Business Service"] --> EncryptedDatabase["Encrypted Database"]
Security Checklist
- HTTPS
- OAuth2
- JWT
- Rate Limiting
- Input Validation
- Logging
- Monitoring
- API Gateway
- RBAC
Scenario 2. A JWT token is stolen. What would you do?
Answer
JWTs cannot normally be revoked immediately, so I would reduce the attack window.
Immediate Actions
- Revoke Refresh Token
- Force user logout
- Rotate signing keys (if necessary)
- Short expiration time
- Audit suspicious requests
Response Flow
flowchart TD
JwtCompromised["JWT Compromised"] --> RevokeRefreshToken["Revoke Refresh Token"]
InvalidateSession["Invalidate Session"] --> InvalidateSession["Invalidate Session"]
GenerateNewJwt["Generate New JWT"] --> GenerateNewJwt["Generate New JWT"]
UserLoginAgain["User Login Again"] --> UserLoginAgain["User Login Again"]
Enterprise Recommendation
Use:
- Short-lived Access Tokens
- Refresh Token Rotation
- Device Tracking
Scenario 3. An attacker is sending thousands of requests per second. How would you protect the application?
Answer
This is a Rate Limiting / DDoS mitigation problem.
Protection Layers
flowchart LR
Internet --> CloudWaf["Cloud WAF"]
CloudWaf["Cloud WAF"] --> ApiGateway["API Gateway"]
ApiGateway["API Gateway"] --> RateLimiter["Rate Limiter"]
RateLimiter["Rate Limiter"] --> Application
Application --> Database
Enterprise Solutions
- AWS WAF
- Cloudflare
- Kong
- Spring Cloud Gateway
- Bucket4j
- Redis Rate Limiting
Scenario 4. Developers accidentally committed database passwords to GitHub.
Answer
Treat this as a security incident.
Response
- Remove credentials.
- Rotate passwords immediately.
- Generate new secrets.
- Update Vault/KMS.
- Audit access logs.
- Scan repositories.
Correct Architecture
flowchart TD
SpringBoot["Spring Boot"] --> AwsKms["AWS KMS"]
SpringBoot["Spring Boot"] --> HashicorpVault["HashiCorp Vault"]
Vault --> DatabasePassword["Database Password"]
Lesson
Secrets should never be stored inside source code.
Scenario 5. Two microservices communicate over HTTP. How would you secure them?
Answer
Internal services should never trust each other.
Secure Communication
flowchart LR
OrderService["Order Service"] --> mTLS
PaymentService["Payment Service"] --> PaymentService["Payment Service"]
PaymentService["Payment Service"] --> JWT
InventoryService["Inventory Service"] --> InventoryService["Inventory Service"]
Enterprise Best Practices
- HTTPS
- mTLS
- JWT Propagation
- Service Mesh
- Service Accounts
Scenario 6. A customer accessed another customer's account using the URL.
Answer
This is a classic Broken Access Control / IDOR vulnerability.
Vulnerability
GET /accounts/1001
↓
GET /accounts/1002
Correct Validation
flowchart TD
User --> JWT
JWT --> ExtractUserId["Extract User ID"]
ExtractUserId["Extract User ID"] --> VerifyResourceOwnership["Verify Resource Ownership"]
VerifyResourceOwnership["Verify Resource Ownership"] --> Allow/Deny
Prevention
- RBAC
- Ownership Validation
- Method-Level Security
Scenario 7. A payment API is processing duplicate transactions.
Answer
The API should support Idempotency.
Solution
Every payment request should include an Idempotency Key.
Payment Flow
flowchart TD
Client --> PaymentRequest["Payment Request"]
PaymentRequest["Payment Request"] --> IdempotencyKey["Idempotency Key"]
IdempotencyKey["Idempotency Key"] --> DatabaseLookup["Database Lookup"]
DatabaseLookup["Database Lookup"] --> AlreadyExists["Already Exists?"]
AlreadyExists["Already Exists?"] --> ReturnPreviousResponse["Return Previous Response"]
Enterprise Benefits
- No duplicate payments
- Safe retries
- Better reliability
Scenario 8. Your application was affected by Log4Shell. What steps would you take?
Answer
Immediate response includes:
- Upgrade Log4j
- Disable vulnerable features
- Scan dependencies
- Redeploy applications
- Monitor logs
- Rotate credentials if necessary
Incident Response
flowchart LR
Vulnerability --> Patch
Patch --> Redeploy
Redeploy --> Monitor
Monitor --> Audit
Prevention
- Dependency scanning
- SCA tools
- Regular upgrades
Scenario 9. How would you secure a cloud-native banking application?
Answer
Enterprise banking applications require multiple security controls.
Banking Architecture
flowchart TD
Customer --> TLS
TLS --> WAF
WAF --> ApiGateway["API Gateway"]
ApiGateway["API Gateway"] --> OAuth2
OAuth2 --> JWT
JWT --> SpringSecurity["Spring Security"]
SpringSecurity["Spring Security"] --> PaymentService["Payment Service"]
PaymentService["Payment Service"] --> AesEncryption["AES Encryption"]
AesEncryption["AES Encryption"] --> Database
Database --> AuditLogs["Audit Logs"]
Security Controls
- MFA
- OAuth2
- JWT
- AES-256
- HSM
- Vault
- mTLS
- SIEM
Scenario 10. Design a secure enterprise microservices platform.
Answer
A Solution Architect should combine multiple security technologies.
Enterprise Architecture
flowchart TD
Users --> HTTPS
HTTPS --> CloudWaf["Cloud WAF"]
CloudWaf["Cloud WAF"] --> LoadBalancer["Load Balancer"]
LoadBalancer["Load Balancer"] --> ApiGateway["API Gateway"]
ApiGateway["API Gateway"] --> OAuth2/OIDC
OAuth2/OIDC --> JWT
JWT --> SpringSecurity["Spring Security"]
SpringSecurity["Spring Security"] --> RBAC
RBAC --> Microservices
Microservices --> mTLS
mTLS --> Kafka
Kafka --> EncryptedDatabase["Encrypted Database"]
EncryptedDatabase["Encrypted Database"] --> AuditLogs["Audit Logs"]
AuditLogs["Audit Logs"] --> SIEM
Security Pipeline
flowchart LR
Authenticate --> Authorize
Authorize --> Validate
Validate --> Encrypt
Encrypt --> Audit
Audit --> Monitor
Monitor --> Respond
Senior Interview Tip
For scenario-based interviews, don't answer with only one technology like JWT or Spring Security.
Instead, explain the complete security strategy:
- HTTPS/TLS 1.3
- Web Application Firewall (WAF)
- API Gateway
- OAuth2 + OpenID Connect
- JWT Authentication
- RBAC & ABAC
- Method-Level Security
- Input Validation
- Rate Limiting
- Mutual TLS (mTLS)
- AES-256 Encryption
- AWS KMS / HashiCorp Vault
- Secure CI/CD (DevSecOps)
- Kubernetes Security
- Logging & Monitoring
- SIEM & Incident Response
- OWASP Top 10 Mitigation
- Zero Trust Architecture
Interviewers are looking for engineers who think beyond coding and can design secure, scalable, resilient enterprise systems.
Quick Revision
- Protect APIs using layered security.
- Use short-lived JWTs and Refresh Token rotation.
- Mitigate DDoS using WAF and Rate Limiting.
- Never store secrets in source code.
- Secure microservices using mTLS.
- Prevent IDOR with ownership validation.
- Use Idempotency Keys for payment APIs.
- Patch vulnerable dependencies quickly.
- Encrypt sensitive banking data using AES-256.
- Design systems using Defense in Depth and Zero Trust principles.