HTML
What is the purpose of a semantic tag?
It gives meaning to content and improves accessibility and SEO.
Why is alt text important?
It helps screen readers describe images and improves accessibility.
What does ARIA stand for?
It stands for Accessible Rich Internet Applications.
What does ARIA help with?
It helps make custom UI components more accessible to assistive
technologies.
Why use <section> instead of
<div>?
A <div> is a generic container with no semantic meaning,
while
<section> groups related content that usually has a heading and gives structure to
the
page.
What is the difference between <article> and
<section>?
An <article> is a self-contained piece of content that
should
still make sense on its own, while a <section> groups related content under a common
theme.
What is <span> used for?
A <span> is an inline element mainly used to style or
target
part of a sentence or word without breaking the flow of text.
JavaScript
Promise vs async/await: main difference?
async/await is syntactic sugar over Promises, making async code look
synchronous;
Promises provide methods like .then/.catch.
How do you handle multiple promises in parallel?
Use Promise.all (or Promise.allSettled) to run promises in parallel and
await
their combined result.
What is a closure?
A function that retains access to the lexical scope in which it was created,
even
after that scope has exited.
Explain event loop microtasks vs macrotasks.
Microtasks (Promises) run after the current task but before the next
rendering;
macrotasks (setTimeout) run later in the queue.
Difference between == and ===?
== performs type coercion before comparison; === checks strict equality
without
coercion.
What's lexical `this` in arrow functions?
Arrow functions do not have their own `this`; they inherit `this` from the
surrounding lexical scope.
When to use Map vs Object?
Map preserves insertion order, accepts any key types, and has size
property—better
for keyed collections than plain objects.
What are generators good for?
Generators allow pausing/resuming function execution and are useful for lazy
sequences and implementing iterators.
How do modules differ from CommonJS require?
ES modules are statically analyzable and use `import`/`export`; CommonJS
loads
modules at runtime with `require`.
What is the difference between let, const, and var?
`var` is function-scoped and hoisted; `let` and `const` are block-scoped,
with
`const` being immutable binding.
What is the difference between null and undefined?
`undefined` means a variable has been declared but not assigned; `null` is
an
assignment value representing no value.
What is the difference between synchronous and asynchronous code?
Synchronous code runs sequentially, blocking further execution until
complete;
asynchronous code allows other operations to run while waiting for tasks to finish.
TypeScript
What is TypeScript?
A superset of JavaScript that adds static typing and compiles to JavaScript.
Difference between type and interface?
Both describe object shapes. Type is more flexible (unions, primitives, intersections). Interface is
commonly
used for object contracts and can be extended.
What is a union type?
A variable that can hold one of several types or literal values using |.
What does ? mean in an interface?
The property is optional.
What does readonly do?
Prevents modifying a property after the object has been created.
Difference between any and unknown?
any disables type checking. unknown requires checking the type before using the value.
What is never?
Represents values that never occur, typically functions that always throw or never finish.
What is Promise<User>?
A Promise that eventually resolves to a User object.
How do you type React props?
Create a type or interface describing the props and use it in the component parameter.
How do you type useState?
useState<User | null>(null) explicitly tells TypeScript the state type.
Why use TypeScript instead of JavaScript?
TypeScript adds static typing, catches errors at compile time, improves autocompletion, and makes large
codebases easier to maintain.
Does TypeScript run in the browser?
No. TypeScript is transpiled into plain JavaScript before running in the browser.
What is the difference between an interface and an object?
An interface is a blueprint used only during compilation. An object is a real value that exists at
runtime.
What is the difference between type and interface?
Both describe object shapes. Type is more flexible because it supports unions, primitives and
intersections.
Interfaces are commonly used for object contracts.
What is a generic?
A generic lets you write reusable code that works with many different types while keeping type safety.
What does <T> represent?
It is a generic type parameter—a placeholder for a type that will be supplied later.
When would you use readonly?
When a property should never be modified after an object has been created.
What does ? mean after a property name?
It makes the property optional.
How do you type React component props?
Create a type or interface for the props and use it in the component parameter.
What does User[] mean?
An array containing User objects.
What does User | null mean?
The value can either be a User object or null.
Why avoid using any?
Because it disables TypeScript's type checking, making it easier for bugs to slip into your code.
CSS
What is the difference between Flexbox and Grid?
Flexbox is for one-dimensional layouts (rows or columns), while Grid is for
two-dimensional layouts (rows and columns).
What is the difference between padding and margin?
Padding is the space between the content and the border of an element, while
margin is the space outside the border, separating the element from other elements.
What are the four parts of the box model?
Content, padding, border, and margin.
What is Flexbox best for?
Laying out items in one dimension, either rows or columns.
What is CSS Grid best for?
Creating two-dimensional layouts with rows and columns.
What does justify-content do in Flexbox?
It aligns items along the main axis (horizontally in a row, vertically in a
column).
What does align-items do in Flexbox?
It aligns items along the cross axis (vertically in a row, horizontally in a
column).
What is the difference between inline, block, and inline-block
elements?
Inline elements do not start on a new line and only take up as much width as
necessary. Block elements start on a new line and take up the full width available. Inline-block
elements
are
like inline elements but can have width and height set.
What is the difference between relative, absolute, fixed, and sticky
positioning?
Relative positions an element relative to its normal position. Absolute
positions it relative to its nearest positioned ancestor. Fixed positions it relative to the viewport.
Sticky
toggles between relative and fixed based on scroll position.
What is the difference between a pseudo-class and a pseudo-element?
A pseudo-class selects elements based on their state (e.g., :hover,
:first-child),
while a pseudo-element selects and styles parts of an element (e.g., ::before, ::after).
What is the difference between em, rem, and px units?
em is relative to the font-size of the parent element. rem is relative to
the
font-size of the root element. px is an absolute unit representing pixels.
React
What triggers a React re-render?
State changes, prop changes, and context updates typically trigger
re-renders.
How is React different from vanilla JavaScript?
Vanilla JavaScript manipulates the DOM directly, while React uses
declarative
components and state to update the DOM efficiently.
When should you use useEffect?
Use it for side effects such as fetching data, subscriptions, timers, and
browser
API synchronization.
When would you choose props over useContext?
Use props for simple, direct data flow between a parent and a child. Use
useContext for shared values that many components need without threading props through every level.
When does useEffect run?
After the component renders, and again when its dependencies change.
What is the difference between context and reducer?
Context shares state, while a reducer centralizes how state changes.
What is the main difference between class and functional components?
Class components use lifecycle methods and this.state; functional components
use
hooks and are usually simpler.
When would you choose a functional component over a class component?
Functional components are preferred for modern React when you want simpler
logic
and hooks-based state/effects.
What is the purpose of a key prop in a list?
It helps React identify which list items changed, were added, or removed,
improving reconciliation.
What is the difference between controlled and uncontrolled components?
Controlled components have their state managed by React, while uncontrolled
components manage their own state internally.
What is the difference between useState and useReducer?
useState is for simple state management, while useReducer is better for
complex
state logic and multiple state transitions.
What is the difference between useEffect and useLayoutEffect?
useEffect runs after the render is committed to the screen, while
useLayoutEffect runs synchronously after all DOM mutations but before the browser paints.
What is the difference between React.memo and useMemo?
React.memo is a higher-order component that memoizes a component to prevent
unnecessary re-renders, while useMemo is a hook that memoizes a value or computation within a component.
Angular
What are Angular components responsible for?
They define the UI, behavior, and template for a specific part of the
application.
What is dependency injection in Angular?
It is a design pattern where Angular provides dependencies to classes
instead
of
having them create them manually.
What is the difference between interpolation and property binding?
Interpolation renders values into text, while property binding updates DOM
properties such as src or disabled.
What are services used for?
Services are used to share logic, data access, and business rules across
multiple
components.
What is RxJS commonly used for in Angular?
It handles asynchronous data streams, HTTP requests, events, and reactive
programming.
What does OnPush change detection do?
It reduces unnecessary checks by only updating the component when its inputs
or
events change.
Security
What is SQL injection?
SQL injection is a code injection technique that exploits vulnerabilities in
an application's software by inserting malicious SQL statements into an entry field for execution. This
can allow attackers to manipulate the database, retrieve sensitive data, or even modify or delete
records.
Give an example of SQL injection?
An example of SQL injection is when a web application fails to properly
sanitize user input, allowing an attacker to insert malicious SQL code. For instance, if a login form
doesn't use parameterized queries, an attacker could enter the following in the username field:
' OR '1'='1
This would bypass authentication and potentially allow unauthorized access to the application.
How do you prevent SQL injection?
To prevent SQL injection, use parameterized queries or prepared statements,
validate and sanitize user inputs, and follow the principle of least privilege when designing database
access.
What is Cross-Site Scripting (XSS)?
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers
to inject malicious scripts into web pages viewed by other users. This can lead to unauthorized actions,
data theft, or session hijacking.
Give an example of Cross-Site Scripting (XSS)?
An example of Cross-Site Scripting (XSS) is when a web application fails to
properly sanitize user input, allowing an attacker to inject a malicious script. For instance, if a
comment section on a website allows users to submit comments without escaping HTML, an attacker could
submit a comment like:
<script>alert('XSS Attack!');</script>
When other users view the comment, the script executes in their browsers, potentially stealing cookies
or
performing other malicious actions.
How do you prevent Cross-Site Scripting?
To prevent Cross-Site Scripting (XSS), sanitize (escape) and validate user
inputs, use Content Security Policy (CSP) headers, encode output when displaying user-provided data, and
implement proper security measures in your web application. Set httpOnly and Secure flags on cookies to
protect against session hijacking.
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack that tricks a user into
performing unintended actions on a web application where they are authenticated. It exploits the trust
that a site has in the user's browser, potentially leading to unauthorized state changes or data
manipulation.
How do you prevent Cross-Site Request Forgery?
To prevent Cross-Site Request Forgery (CSRF), use anti-CSRF tokens,
implement
the SameSite cookie attribute, validate the origin of requests, and ensure that state-changing
operations
require explicit user confirmation.
Give an example of Cross-Site Request Forgery?
A common example is when a user is logged into their bank account and visits
a
malicious website. The malicious site could include a hidden form that submits a transfer request to the
bank's server without the user's knowledge or consent.
What is the difference between Cross-Site Scripting and Cross-Site
Request Forgery?
Cross-Site Scripting (XSS) involves injecting malicious scripts into web
pages
viewed by other users, while Cross-Site Request Forgery (CSRF) tricks a user into performing unintended
actions on a web application where they are authenticated.
What is IDOR? What does it stand for?
IDOR stands for Insecure Direct Object Reference. It occurs when an
application uses user-supplied input to access objects directly, without proper authorization checks.
Give an example of IDOR?
An example of IDOR is when a user can access another user's account
information by simply changing the ID parameter in the URL, such as `https://example.com/user/123` to
`https://example.com/user/456`.
IDOR vs BOLA
IDOR (Insecure Direct Object Reference) occurs when an application uses
user-supplied input to access objects directly, without proper authorization checks. BOLA (Broken Object
Level Authorization) is a more specific type of IDOR where the authorization check is bypassed at the
object level. In essence, BOLA is a subset of IDOR for API endpoints.
what is p95/p99?
P95 and P99 are performance metrics that represent the 95th and 99th
percentiles of response times in a system. P95 indicates that 95% of requests are faster than this time,
while P99 indicates that 99% of requests are faster. These metrics help identify outliers and assess
system performance under load.
explain the difference between 401 and 403?
401 Unauthorized indicates that the user is not authenticated, while 403
Forbidden indicates that the user is authenticated but does not have permission to access the requested
resource.
explain the difference between 400 and 500?what typically causes
each?
400 Bad Request indicates that the client sent a malformed request, while
500
Internal Server Error indicates that the server encountered an unexpected condition that prevented it
from
fulfilling the request.
explain POST vs PUT vs PATCH
POST is used to create a new resource, PUT is used to update an existing
resource, and PATCH is used to make partial updates to an existing resource.
In which case is it dangerous to use PUT instead of PATCH? and why?
Using PUT instead of PATCH can be dangerous when you want to update only
specific fields of a resource. PUT replaces the entire resource with the new data, which can lead to
unintentional loss of data if not all fields are provided. PATCH, on the other hand, allows for partial
updates, modifying only the specified fields while leaving the rest of the resource intact.
is POST idempotent? and why?
POST is not idempotent because each request creates a new resource. If you
make the same POST request multiple times, it will create multiple resources with different IDs.
What is a parameterized query? give an example.
A parameterized query is a query that uses parameters to replace values,
preventing SQL injection attacks. For example, instead of concatenating user input directly into a query
string, you would use a parameterized query like `SELECT * FROM users WHERE id = ?` and pass the user
input as a parameter.
How would you validate the input of a client review form to prevent
XSS
attacks?Give an example of code escaping a <script> tag.
To prevent XSS attacks, you should sanitize user input by escaping HTML
characters and using a whitelist of allowed tags and attributes.