skip to content

Security

Java's own security machinery: the JCA/JCE crypto stack, the serialization attack surface, and the legacy SecurityManager access-control model. Interviewers use this area to check that you can apply crypto correctly through real APIs rather than describe it abstractly.

part ofJavaoverview, primer and where to startread it →
on this pageshow

explore

questions

63 · 4 sections

How does Java prevent SQL injection, and why does string concatenation of SQL fail to do so?

level: juniorimportance: must knowfreq 88%
basics
~20 s

Never build SQL by gluing user input into the query text. Use PreparedStatement with ? placeholders (or JPA named parameters) and bind values separately, so input is treated as data, not as code the database runs.

open as a page

How do you prevent path traversal in Java when building a file path from user-supplied input?

level: middleimportance: must knowfreq 70%
basics
~10 s

Don't trust the input filename. Resolve the full real path (Path.normalize or File.getCanonicalPath), then check it actually stays inside your intended base directory before opening it. Reject anything that escapes, like ../ sequences.

open as a page

What role does Bean Validation (JSR-380) play in securing a Java application, and what are its limits as a security control?

level: middleimportance: should knowfreq 55%
basics
~20 s

Bean Validation (annotations like @NotNull, @Size, @Pattern, @Email on fields, triggered by @Valid) checks that incoming data has the expected shape at the edge of your app. It reduces bad/malicious input but does not replace output-side defenses like parameterized SQL or encoding.

open as a page

Why is ProcessBuilder with an argument array safer than Runtime.exec with a shell string for running external programs?

level: middleimportance: should knowfreq 62%
basics
~20 s

Passing a single command string to a shell lets attacker input add extra commands (via ; | && etc.). ProcessBuilder with a list of separate arguments runs the program directly with no shell, so each argument stays one literal value.

open as a page

Why are passwords and secrets handled as char[] rather than String in Java, and how do you clear them?

level: seniorimportance: should knowfreq 48%
basics
~20 s

Strings in Java are immutable and you can't erase them, so a secret stays in memory until garbage collection happens, exposed in heap dumps. A char[] is mutable, so you can overwrite it with Arrays.fill right after use to shorten the exposure.

open as a page

When encrypting and decrypting with RSA in Java, which key do you init the Cipher with, and what is the role of ENCRYPT_MODE vs DECRYPT_MODE?

level: juniorimportance: must knowfreq 55%
basics
~10 s

To encrypt, init the Cipher in ENCRYPT_MODE with the recipient's public key. To decrypt, init in DECRYPT_MODE with the matching private key. Public key locks, private key unlocks.

open as a page

How do you create a Cipher for AES in Java, and what does the transformation string passed to Cipher.getInstance mean?

level: juniorimportance: must knowfreq 70%
basics
~10 s

You call Cipher.getInstance with a transformation string like "AES/GCM/NoPadding". It has three parts: the algorithm (AES), the mode (how blocks are chained, e.g. GCM or CBC), and the padding (e.g. PKCS5Padding or NoPadding).

open as a page

How do you generate a symmetric secret key in Java using KeyGenerator, and what does init() control?

level: juniorimportance: must knowfreq 60%
basics
~10 s

Ask KeyGenerator for an algorithm like AES, call init() with the key size (for example 256 bits), then generateKey(). It returns a SecretKey you use to encrypt and decrypt.

open as a page

How do you compute a cryptographic hash in Java using the MessageDigest API? Walk through the getInstance / update / digest lifecycle.

level: juniorimportance: must knowfreq 70%
basics
~10 s

Call MessageDigest.getInstance("SHA-256") to get an engine, feed bytes with update(...), then call digest() to get the final hash as a byte[]. digest() finishes the computation and resets the engine for reuse.

open as a page

How should you generate the salt for PBKDF2 in Java, and why does the choice of random source matter?

level: juniorimportance: must knowfreq 50%
basics
~20 s

Use java.security.SecureRandom to fill a fresh byte array (16 bytes) for each password. Don't use java.util.Random or Math.random - they're predictable. The salt is stored with the hash and doesn't need to be secret, just unique and random.

open as a page

Why can calling ObjectInputStream.readObject() on attacker-controlled bytes lead to remote code execution, even when the expected class looks harmless?

level: middleimportance: must knowfreq 70%
basics
~20 s

readObject() rebuilds objects from raw bytes and runs special hook methods (like readObject/readResolve) on each class while doing so. An attacker sends bytes describing other classes already on your classpath, and those hooks run code the attacker chose.

open as a page

What is JEP 290, and how do ObjectInputFilter and setObjectInputFilter let you constrain which classes are deserialized?

level: seniorimportance: must knowfreq 60%
basics
~20 s

JEP 290 added a built-in filter to Java that runs while reading a serialized stream and decides, class by class, whether each class is allowed before it is created. You configure an allowlist so only expected classes pass; everything else is rejected, blocking most gadget-chain attacks.

open as a page

How do Serializable, the transient keyword, and serialVersionUID work, and what are their security-relevant implications?

level: juniorimportance: should knowfreq 55%
basics
~20 s

Serializable is a marker that says a class can be turned into bytes. transient marks a field to be skipped when serializing (so secrets aren't written). serialVersionUID is a version number used to check that the saved bytes match the current class. None of them, by themselves, makes deserialization safe.

open as a page

What is the 'look-ahead deserialization' pattern, and how would you implement it without JEP 290?

level: seniorimportance: should knowfreq 40%
basics
~20 s

Look-ahead deserialization means checking the name of each class in the stream before that class is actually created, and refusing any class you didn't expect. Before JEP 290 you did this by subclassing ObjectInputStream and overriding resolveClass to validate the class name and throw if it's not allowed.

open as a page

You inherited a service that accepts Java-serialized objects over HTTP. How do you prioritize remediating the deserialization risk, and why is filtering not the first answer?

level: principalimportance: should knowfreq 35%
basics
~20 s

The best fix is to stop using Java native serialization for untrusted input and switch to a data-only format like JSON or Protocol Buffers parsed into known types. Class filters (JEP 290) and gadget removal are good extra layers, but they only reduce the risk; they don't remove the dangerous code-execution surface.

open as a page

What is a Java Permission, and how does a .policy file grant permissions to code?

level: juniorimportance: should knowfreq 30%
basics
~20 s

A Permission is an object that names one capability the code is allowed to use, like reading a file or opening a network connection. A .policy text file lists grant blocks that hand those capabilities to code from a given location.

open as a page

What does it mean to seal a package in a JAR, and how do you configure it in the manifest?

level: middleimportance: should knowfreq 22%
basics
~20 s

Sealing a package means every class in that package must come from the same JAR file. You turn it on by adding 'Sealed: true' to the JAR's MANIFEST.MF, for one package or the whole archive.

open as a page

Why would you sign a JAR, and what security property does a signature actually give you?

level: middleimportance: should knowfreq 30%
basics
~10 s

Signing a JAR attaches a digital signature so you can prove who published it and that nobody changed its files afterward. It gives integrity and authenticity — not secrecy.

open as a page

Why was the SecurityManager deprecated for removal in JEP 411, and what are the modern replacements?

level: middleimportance: should knowfreq 40%
basics
~20 s

JEP 411 (Java 17) deprecated the SecurityManager for removal because its main job — sandboxing browser applets — no longer exists, it was hard to use correctly, and it slowed down the whole JDK. Today you isolate untrusted code with the operating system or containers, and use the Java module system for encapsulation.

open as a page

What is a ProtectionDomain, and how do the permissions of code on the call stack get combined during an access check?

level: seniorimportance: should knowfreq 22%
basics
~20 s

A ProtectionDomain groups code from the same source with the permissions granted to it. When code is checked, Java looks at every method on the call stack and only allows the action if every one of them has the permission — the most restrictive caller wins.

open as a page