Authentication & Authorization Flashcards
6 cards from real ASP.NET Core practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Authentication & Authorization flashcards as text
Which attribute restricts access to authenticated users only in ASP.NET Core?
Answer: [Authorize]
[Authorize] applies the default authorization policy, denying access to unauthenticated users with a 401 or redirect.
What does [AllowAnonymous] do when placed on an action inside an [Authorize] controller?
Answer: Overrides the controller-level authorization, allowing unauthenticated access to that action
[AllowAnonymous] takes precedence over any [Authorize] attributes, allowing the action to bypass authentication checks.
Which middleware must be added before UseAuthorization() for authentication to work?
Answer: UseAuthentication()
UseAuthentication() must precede UseAuthorization() so that user identity is established before authorization policies are evaluated.
What is the purpose of JWT Bearer authentication in ASP.NET Core APIs?
Answer: To validate tokens sent in the Authorization header and set the user identity
JWT Bearer middleware validates the signed JSON Web Token and populates HttpContext.User with claims from the token payload.
Which method adds ASP.NET Core Identity to the application?
Answer: services.AddIdentity()
AddIdentity() registers Identity services including user management, password hashing, and role management.
What does [Authorize(Roles = "Admin")] do in ASP.NET Core?
Answer: Restricts the action to users who have the Admin role claim
The Roles parameter checks the user's role claims and returns 403 Forbidden if the user does not have the specified role.