Question 1
In a Next.js application using sessions, you check session.user.email in your API route. What are you verifying primarily?
The user’s identity has been authenticated
The user is authorized to perform the action
The user’s role has been confirmed via RBAC
The session has expired
Question 2
You have an API route in Next.js that does if (session?.user.role !== 'admin') return res.status(403). What concept does this implement?
Authentication
Session hijacking prevention
Permission escalation
Role‐based access control (RBAC)
Question 3
Which of the following best describes the difference between authentication and authorization?
Authentication determines what you can do; authorization determines who you are.
Authentication verifies you are who you claim; authorization grants you access to what you are allowed.
Authentication is only handled on the client-side; authorization is only on the server-side.
They are synonyms and can be used interchangeably.
Question 4
In a Next.js app using JWT sessions, you include the user’s role inside the token (token.role = user.role). Which of the following is true?
You are implementing authentication only
You are storing authorization information inside the session token
This makes authentication unnecessary
This means the user automatically becomes a super-admin
Question 5
Suppose you protect a Next.js route with middleware:
if (!session) return redirect('/login');
if (session.user.role !== 'manager') return redirect('/unauthorized');
What step(s) does this code cover?
Authentication only
Authorization only
Both authentication and authorization
Neither
Question 6
Why is RBAC (Role-Based Access Control) preferred in large applications?
Because it allows each user to be given permissions individually with no roles
Because it entirely replaces authentication
Because it groups users into roles and assigns permissions to the roles - simpler management
Because it makes databases run faster
Question 7
In Next.js, you want to enforce that only users with the role “editor” can update articles. Which approach is least secure?
Hiding the “Edit” button in the UI if user.role !== 'editor'.
Checking session.user.role === 'editor' inside the API route before update.
Database layer check: when performing update, verify user role is ‘editor’ in the DB trigger.
Middleware that denies access with 403 if the role is not ‘editor’.
Question 8
You implement session strategy as stateless in Next.js (cookie / JWT) vs database sessions. Which statement is correct?
Stateless sessions store user role only in server memory.
Database sessions store session ID in a cookie, and session data in DB for verifying later.
Stateless sessions cannot include roles in the token.
Database sessions are always slower and less secure.
Question 9
Which HTTP status code is most appropriate when a user is authenticated but does not have permission (role) to access a resource?
401 Unauthorized
403 Forbidden
404 Not Found
500 Internal Server Error
Question 10
You’re using NextAuth.js (Auth.js) in Next.js to implement RBAC. You fetch user roles in the jwt callback and then add them to the session in session callback. Why is this needed?
To allow client-side code to access session.user.role for UI decisions
To make authentication skip password check
To store the user’s password in the session
To bypass server-side authorization checks
There are 10 questions to complete.