20 questions · sample answers

Developer interview questions and answers

Developer interviews test whether you can build and ship working web or app features: how the browser and server talk, one framework in depth, APIs, databases, debugging and Git. Expect a live coding task or a take-home project, then questions on your own code. Use this page to practise the 20 questions below out loud, compare your answers with the samples, and prepare for the follow-ups each one usually leads to.

Most developer hiring runs as an online coding test or take-home assignment, one or two technical rounds with senior developers, sometimes a managerial round, and a final HR discussion.

Last updated

Developer interview questions and answers
Round
Level

20 of 20 questions shown

Role and technical questions

What happens, step by step, when you type a URL into the browser and press Enter?

Role Fresher

What they’re checking: Whether you understand the full request path, from DNS to rendering, which shows you can reason about where a web bug or slowdown actually lives.

Sample answer

First the browser checks its cache, then resolves the domain to an IP address through DNS. It opens a TCP connection, and for HTTPS it does a TLS handshake to agree on encryption. Then it sends an HTTP GET request with headers and cookies. The server, say Nginx in front of a Node or Laravel app, runs the route and returns HTML with a status code like 200. The browser parses the HTML into the DOM, fetches CSS, JavaScript and images, builds the render tree, lays out the page and paints it. Scripts can then call APIs and update the page.

Likely follow-ups
  • Where does a CDN fit into this flow?
  • What changes with HTTP/2?

What is the difference between var, let and const in JavaScript?

Role Fresher

What they’re checking: Basic JavaScript fluency: scope, hoisting and reassignment, and whether you know the classic loop-closure bug that var causes in real code.

Sample answer

var is function-scoped and hoisted, so it is available as undefined before the line where it is declared. let and const are block-scoped, and touching them before declaration throws an error because of the temporal dead zone. let can be reassigned, const cannot. But const does not freeze objects, so I can still push into a const array. The practical bug I have seen is a for loop with var and a setTimeout inside: every callback prints the final value. Switching to let gives each iteration its own binding. In my projects I use const by default and let only when a value changes.

Likely follow-ups
  • How would you make an object truly immutable?
  • What is a closure?

How would you design a REST API for a simple to-do app?

Role

What they’re checking: Whether you use HTTP methods, resource URLs and status codes correctly and think about validation, auth and pagination, not just the happy path.

Sample answer

I would model tasks as a resource. GET /api/tasks lists the logged-in user’s tasks with pagination, GET /api/tasks/{id} returns one, POST /api/tasks creates one and returns 201 with the new task, PATCH /api/tasks/{id} updates fields like title or done, and DELETE returns 204. Validation errors return 422 with field messages, a missing task returns 404, and a task owned by someone else returns 403. Every route sits behind token auth. I would add filters like ?done=false, version the API under /v1, and keep responses in one consistent JSON shape so the frontend can handle errors in one place.

Likely follow-ups
  • When would you choose PUT over PATCH?
  • How would you add rate limiting?

A feature works on your machine but breaks in production. How do you debug it?

Role Experienced

What they’re checking: Your debugging method under pressure: reading logs, checking environment differences and reproducing safely instead of guessing and pushing random fixes.

Sample answer

I start with evidence, not guesses. I check the error tracker and server logs for the exact stack trace and time. Then I list what differs between local and production: environment variables, PHP or Node version, database data, caching, file permissions and third-party keys. Last year an image upload failed only in production because the server had a 2 MB upload limit in php.ini while my local limit was higher. If logs are not enough, I reproduce on staging with a copy of production config. Once fixed, I add a log line or test so the same failure is caught earlier next time.

Likely follow-ups
  • What would you log, and what would you never log?
  • How do you roll back a bad deploy?

What is CORS, and how do you fix a CORS error?

Role

What they’re checking: Whether you understand that CORS is a browser security rule enforced from server headers, and that you fix it on the server rather than disabling security.

Sample answer

CORS is the browser’s rule for letting a page on one origin call an API on another origin. Origin means scheme, domain and port together, so localhost:3000 calling localhost:8000 is cross-origin. The browser sends the request, or first a preflight OPTIONS request for things like JSON bodies or custom headers, and only lets the page read the response if the server replies with the right Access-Control-Allow-Origin header. So the fix belongs on the API server: allow the specific frontend origins, methods and headers, and allow credentials only if cookies are needed. I avoid a wildcard origin on authenticated APIs.

Likely follow-ups
  • Why does Postman not show CORS errors?
  • What triggers a preflight request?

A page takes six seconds to load. How would you make it faster?

Role

What they’re checking: Whether you measure before optimising and know the common frontend and backend fixes, rather than reaching for one favourite trick.

Sample answer

I would measure first with Lighthouse and the browser Network tab to see if the delay is server time, large files or blocking scripts. If the first byte is slow, I look at the backend: slow queries, missing indexes, N+1 queries, and whether results can be cached. On the frontend, I compress and resize images, serve WebP, lazy-load images below the fold, split JavaScript bundles so each page loads only what it needs, and defer non-critical scripts. On one e-commerce project, adding an index on the orders table and converting product images to WebP took the listing page from about five seconds to under two.

Likely follow-ups
  • What are Core Web Vitals?
  • How would you find an N+1 query?

When would you use a SQL database and when would you use a NoSQL database?

Role

What they’re checking: Whether you choose storage based on data shape, relationships and consistency needs, instead of following trends or naming a tool you happen to know.

Sample answer

I pick SQL, like MySQL or PostgreSQL, when data has clear relationships and I need joins, transactions and strong consistency, for example orders, payments and users. Foreign keys and constraints protect the data. I pick a document store like MongoDB when records vary in shape and are read as a whole, such as product catalogues with different attributes per category, or activity logs. A key-value store like Redis fits sessions, caching and counters. In most web apps I start with PostgreSQL because it also handles JSON columns well, and I add Redis for caching only when I can show a need.

Likely follow-ups
  • What is a database transaction?
  • How do indexes speed up queries?

How do you handle user authentication in a web app? Sessions or JWT?

Role Experienced

What they’re checking: Whether you understand the security trade-offs of each approach, including storage, expiry, revocation and common attacks like XSS and CSRF.

Sample answer

For a normal server-rendered or same-domain app I prefer sessions. The server stores the session, the browser gets an HttpOnly, Secure cookie, and logout or revoking access is immediate. I add CSRF tokens for forms. JWTs suit mobile apps or separate APIs where the server should stay stateless, but they are hard to revoke, so I keep access tokens short-lived, around 15 minutes, with a refresh token stored securely and rotated on use. I never put JWTs in localStorage for a sensitive app because any XSS can read them. Passwords are hashed with bcrypt or Argon2, never encrypted.

Likely follow-ups
  • What is the difference between hashing and encryption?
  • How would you add login with OTP?

Explain the JavaScript event loop and how async/await works.

Role

What they’re checking: Whether you understand how single-threaded JavaScript handles waiting work, which explains many ordering bugs and frozen interfaces in real apps.

Sample answer

JavaScript runs on one main thread with a call stack. Slow work like network calls or timers is handed to the browser or Node, and when it finishes, a callback is queued. The event loop moves queued work onto the stack only when the stack is empty. Promise callbacks go in the microtask queue, which runs before timers in the macrotask queue, so a resolved promise logs before setTimeout with zero delay. async/await is cleaner syntax over promises: await pauses that function, not the whole thread. A heavy loop still blocks everything, so for large calculations I would use a Web Worker.

Likely follow-ups
  • What does Promise.all do if one promise fails?
  • How do you run three API calls in parallel?

How do you protect a web app against SQL injection and XSS?

Role

What they’re checking: Basic security hygiene: whether you know the root cause of each attack and the standard defences built into modern frameworks.

Sample answer

SQL injection happens when user input is joined into a query string. I prevent it by always using parameterised queries or the ORM’s query builder, like Eloquent or Prisma, and never building SQL with string concatenation. For XSS, the risk is user input rendered as HTML or script. I rely on the template engine’s automatic escaping, avoid innerHTML and raw output unless the content is sanitised with a library, and set a Content Security Policy header. I also validate input on the server, not only in the browser, and give the database user only the permissions the app needs.

Likely follow-ups
  • What is CSRF and how is it different?
  • Where would you store API keys?

How do you use Git when working in a team?

Role Fresher

What they’re checking: Whether you can work safely in a shared codebase with branches, pull requests and conflict resolution, which matters from your first week.

Sample answer

I pull the latest main branch and create a feature branch named after the ticket, like feature/cart-coupon. I make small commits with clear messages, push the branch and open a pull request with a short description and screenshots if the UI changed. After review comments, I push fixes to the same branch. If there is a merge conflict, I pull main into my branch, open the conflicting files, keep the correct lines from both sides, run the app and tests, then commit. In my final-year project with three teammates, this workflow stopped us overwriting each other’s code.

Likely follow-ups
  • What is the difference between merge and rebase?
  • How do you undo a commit that was already pushed?

Behavioural questions

Tell me about a bug that took you a long time to find.

Behavioural

What they’re checking: Your persistence and method when stuck, and whether you learned something that changed how you work, not just that you eventually fixed it.

Sample answer

On a food-ordering app, some users were charged twice about once a week. It never happened in testing. I added logging around the payment callback and found the gateway sometimes sent the same success webhook twice within a second. Both requests passed our check for an unpaid order because neither had saved yet. I fixed it by making the webhook handler idempotent: a unique constraint on the gateway payment ID and a database transaction with a row lock on the order. Double charges stopped. Since then I assume any external callback can arrive twice and design for it.

Likely follow-ups
  • How did you refund the affected users?
  • What does idempotent mean?

Describe a time you had to learn a new framework or language quickly.

Behavioural Fresher

What they’re checking: How you learn under time pressure, and whether you can become productive in an unfamiliar stack without needing everything taught to you.

Sample answer

During my internship at a small agency, the client project was in Vue, and I had only used React. I had eight days before my first task. I did the official Vue tutorial on the first two days, then read our existing components to learn how the team structured things. I rebuilt one small screen in a sandbox and asked my mentor to review it. By the second week I shipped a filter panel for the product list. The lesson I took is to learn from the team’s real code, not only from tutorials.

Likely follow-ups
  • What differences did you notice between Vue and React?
  • How do you usually learn a new tool?

Tell me about a time you broke something in production.

Behavioural Experienced

What they’re checking: Honesty and ownership, how calmly you recover, and whether you improved the process afterwards so the same mistake cannot happen again.

Sample answer

I once deployed a database migration that renamed a column, and the old app servers were still running during the deploy, so checkout failed for around ten minutes. I noticed the error spike, told the team lead in the channel right away, and rolled back the release. Then I wrote the change in two steps: first add the new column and write to both, deploy, then remove the old one in a later release. I also added a checklist item for backward-compatible migrations to our pull request template. No one on the team has repeated that mistake since.

Likely follow-ups
  • How did you tell the business side?
  • What is a zero-downtime deployment?

Describe a disagreement with a designer or product manager about a feature.

Behavioural

What they’re checking: Whether you can push back with facts, find a middle path and keep a working relationship, instead of silently building something you think is wrong.

Sample answer

Our product manager wanted infinite scroll on the order history page. I felt it would hurt users who needed to find an old order and would make the page footer unreachable. Rather than argue, I built a quick prototype of both options and we checked support tickets, which showed people mostly searched for specific orders. We agreed on paginated results with a search box and a date filter. The PM presented it to the business as her decision, which was fine with me. I learned that a working demo settles arguments faster than opinions.

Likely follow-ups
  • What if she had insisted on her version?
  • How do you estimate work you disagree with?

Tell me about a time a release was delayed because of your work.

Behavioural Experienced

What they’re checking: Whether you flag risk early, own estimation mistakes and change how you plan, rather than blaming requirements or teammates.

Sample answer

I estimated three days to integrate a new SMS provider, but their API documentation was out of date and callbacks behaved differently from what was written. By day two I knew I would not finish, so I told my lead the same afternoon instead of on the deadline. We moved the SMS feature to the next release and shipped the rest on time. I raised a support ticket with the provider and finished in five days. Now, for any third-party integration, I spend the first half day building a small proof of concept before I give an estimate.

Likely follow-ups
  • How do you estimate tasks now?
  • How did the client react?

Tell me about a time you explained a technical problem to a non-technical client.

Behavioural

What they’re checking: Whether you can translate technical issues into business impact and plain language, which matters in client-facing and small-team roles.

Sample answer

A school owner asked why his website went down whenever results were announced. Instead of talking about servers and CPU, I compared the shared hosting plan to a small shop with one counter: fine on normal days, but on results day three thousand parents arrive at once. I showed him two options with monthly costs: move to a slightly bigger server, or publish results as a static page through a CDN. He chose the CDN option because it was cheaper. On the next results day the site stayed up, and he now calls me before any big announcement.

Likely follow-ups
  • How do you explain delays to a client?
  • How do you handle scope creep?

HR round questions

What are your salary expectations for this developer role?

HR

What they’re checking: Whether you have researched the market for your stack and experience and can state a reasoned range without underselling or being rigid.

Sample answer

I have looked at openings for full-stack developers with about three years of React and Node experience in Pune, and similar roles are offering roughly 12 to 15 lakh per annum. My current CTC is 9.5 lakh. Given that this role adds cloud deployment and on-call responsibility, I am looking for something in the range of 13 to 14 lakh fixed. I am open to discussing the split between fixed pay and variable, and I would also like to understand the learning budget and the review cycle before I decide.

Likely follow-ups
  • Is that number negotiable?
  • Do you have other offers in hand?

What is your notice period, and can you join earlier?

HR Experienced

What they’re checking: Your real availability, whether you respect your current employer’s terms, and whether any early-joining promise you make is realistic.

Sample answer

My notice period is 60 days as per my contract. I have already discussed a handover plan with my manager: I am finishing a payment module release in the first three weeks, and after that I can document my work and hand over to a teammate. Based on that, I could ask for an early release after about 45 days, but I would not promise it until my manager agrees. If you need someone sooner, I am happy to do a short onboarding call or read your codebase docs before I join.

Likely follow-ups
  • Would you consider buying out your notice?
  • Are you interviewing elsewhere?

Why do you want to join our company as a developer?

HR

What they’re checking: Whether you have researched the product and tech stack, and whether your reasons are about the work rather than only salary or location.

Sample answer

I have used your billing app for my freelance invoices, so I know the product from the user side. I read your engineering posts about moving the invoice screens to React and adding offline support for small shop owners with weak internet. That is the kind of problem I want to work on: real users, real constraints, not only internal dashboards. My current work is mostly maintaining an old admin panel, and I want to build customer-facing features at scale. Your stack of React, Node and PostgreSQL also matches what I have used for the last two years.

Likely follow-ups
  • What would you improve in our app?
  • Where do you see yourself in three years?

Practise these questions
Answer them aloud against a timer, then compare with the sample answers.

Start practice →

How to prepare for a developer interview

  • Revise one framework deeply rather than five shallowly. Be ready to explain lifecycle, state management and routing in the framework listed on your resume.
  • Keep two projects you can open and walk through live, including the database schema, API routes and one bug you fixed.
  • Practise coding on a plain editor without autocomplete, speaking your thinking out loud, because many live rounds run on shared editors.
  • Revise HTTP status codes, REST conventions, SQL joins and indexes, since these come up in almost every web developer round.
  • Clean up your GitHub: pinned repositories with a README, setup steps and screenshots help interviewers prepare questions about your real work.

Skill tests for developers

Timed practice tests with answers and explanations, for the written or online round.

One place for your job

Everything for developers

FAQ

Questions about developer interviews

Most include a coding test or take-home assignment, one or two technical rounds on your framework, APIs, databases and debugging, and an HR round. Some add a managerial round about teamwork and estimates. Freshers get more questions on JavaScript basics, data structures and their projects, while experienced developers are asked about architecture choices, production issues and code quality.

Build two complete projects with a frontend, an API and a database, and deploy them. Revise JavaScript fundamentals like closures, promises and the event loop, plus basic SQL. Practise easy array and string problems. Be ready to explain every line of your project code, because interviewers often ask you to change something in it live.

Yes, especially at product companies and startups. They usually ask you to build a small feature in a few hours or a couple of days. Keep the scope tight, write a clear README with setup steps and trade-offs you made, add a few tests, and commit in small steps. Expect the next round to discuss your choices.

Give the interviewer a link to your work

A personal website with your resume, projects and certificates — live in about five minutes.

● Live in 5 minutes · free to start · no auto-renew

Recruiters Google you before the interview

Get a page that shows up: your experience, projects and contact details at your own link. Live in minutes.

Start free
Chat on WhatsApp