โ† All ASP.NET Core Flashcard Decks

Authentication & Authorization Flashcards

6 cards from real ASP.NET Core practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Authentication & Authorization flashcards as text
  1. What is a claims-based identity in ASP.NET Core?

    Answer: An identity made up of key-value pairs (claims) representing user properties

    Claims are name-value pairs attached to a ClaimsIdentity that represent facts about the user, such as name, email, or roles.

  2. What does the IAuthorizationService interface provide in ASP.NET Core?

    Answer: Programmatic authorization checks against policies or requirements

    IAuthorizationService.AuthorizeAsync() allows imperative authorization checks in services or controllers beyond attribute-based authorization.

  3. Which class is the base for custom authorization requirements in ASP.NET Core?

    Answer: IAuthorizationRequirement

    IAuthorizationRequirement is a marker interface implemented by requirement classes used in custom authorization policies.

  4. What is an authorization policy in ASP.NET Core?

    Answer: A named set of requirements that must all be met for access to be granted

    Policies combine one or more IAuthorizationRequirement objects and are registered by name using AddAuthorization().

  5. How do you configure cookie authentication in ASP.NET Core?

    Answer: services.AddAuthentication().AddCookie()

    AddAuthentication() registers the auth framework and AddCookie() configures the cookie authentication handler with its options.

  6. What is the purpose of the ClaimsPrincipal in ASP.NET Core?

    Answer: It represents the current user, holding one or more ClaimsIdentity objects

    ClaimsPrincipal is the container for the user's identities and is available via HttpContext.User throughout a request.