Frequently asked full stack developer interview questions across JavaScript, React, Node, APIs and databases — with concise answers. Practise them in a free AI mock interview.
Practise these in a free AI mock interviewProps are read-only data passed from a parent to a child. State is data a component owns and can change over time. Updating state re-renders the component; props change only when the parent passes new values.
JavaScript is single-threaded; the event loop lets it handle async work. Synchronous code runs on the call stack; promise callbacks wait in the microtask queue and timer callbacks in the macrotask queue, running when the stack is empty. Microtasks run before the next macrotask.
DNS resolves the domain to an IP, a TCP (and TLS) connection is made, the browser sends an HTTP request, the server responds with HTML, then the browser parses HTML/CSS/JS, builds the DOM and renders — fetching linked assets along the way.
Never concatenate user input into queries. Use parameterised queries / prepared statements (or an ORM), validate and sanitise input, and give the database account least privilege.
REST uses HTTP verbs (GET/POST/PUT/DELETE) on resources identified by URLs, returning representations (usually JSON). A RESTful API is stateless, resource-oriented, and uses correct status codes.
SQL databases are relational with fixed schemas and strong consistency — great for structured, related data and transactions. NoSQL offers flexible schemas and horizontal scale — great for large, evolving or unstructured data. Choose by data shape and scale needs.
Hooks let function components use state and lifecycle features: useState for local state, useEffect for side effects, useContext for shared data, useMemo/useCallback for performance. They must be called at the top level, not conditionally.
Measure first (Lighthouse/DevTools). Then compress/lazy-load assets, code-split JS, cache (CDN + HTTP caching), reduce re-renders, add DB indexes for slow queries, and avoid blocking the main thread.
Cross-Origin Resource Sharing — a browser rule that blocks a page from calling a different origin unless that server returns the right Access-Control-Allow-Origin headers. You fix it on the server, not the browser.
Authentication verifies who you are (login). Authorization decides what you are allowed to do (roles/permissions). You authenticate first, then authorize each action.
var is function-scoped and can be redeclared; let and const are block-scoped. const cannot be reassigned, though an object it points to can still mutate. Prefer const, then let, and avoid var.
A closure is a function that remembers variables from the scope where it was created, even after that scope has finished running. It is how JavaScript supports data privacy and function factories.
== compares after converting types, so "5" == 5 is true. === compares value and type with no conversion, so "5" === 5 is false. Prefer === to avoid surprises.
A promise represents a value that will arrive later (pending, then fulfilled or rejected). async/await is syntax that lets you write promise-based code that reads top to bottom, using try/catch for errors.
A lightweight in-memory copy of the UI. React compares the new virtual DOM to the previous one and updates only the parts of the real DOM that changed, which is faster than re-rendering everything.
Keys give each item a stable identity so React can tell which items changed, were added or removed, and update efficiently. Using the array index as a key can cause bugs when the list reorders.
Functions that run in order on each request, with access to req, res and next(). They handle cross-cutting concerns — logging, authentication, body parsing, error handling — before the route handler runs.
A JSON Web Token is a signed token holding user claims. On login the server issues it, the client sends it on each request, and the server verifies the signature to authenticate the user without storing session state.
An index speeds up reads on a column, like a book index. Add them on columns used in WHERE, JOIN or ORDER BY, but not everywhere, since indexes slow down writes and use extra storage.
Cookies are sent to the server on every request and suit auth. localStorage persists in the browser until cleared; sessionStorage lasts only for the tab. Only cookies are automatically sent to the server.
PUT replaces the whole resource with the payload; PATCH updates only the fields you send. PUT is designed to be idempotent; PATCH usually is too, depending on the operation.
Validate input, wrap async handlers so rejected promises are caught, use a central error-handling middleware, return correct status codes with clear messages, and log errors on the server without leaking internals to the client.
It tells React when to re-run the effect. An empty array runs it once on mount; listing values runs it whenever they change; omitting the array runs it after every render. Missing dependencies cause stale-data bugs.
Debounce waits until the user stops triggering an event before running (good for search-as-you-type). Throttle runs at most once per interval (good for scroll or resize). Both limit how often expensive work runs.
200 for success, 201 for created, 400 for a bad or validation request, 401 for not authenticated, 403 for not authorised, 404 for not found, and 500 for a server error. Correct codes make an API predictable.
Knowing the answers isn’t enough — say them out loud
Practise these Full Stack questions in a free AI mock interview: answer by voice, get instant feedback on your strengths and the gaps to fix.
Admissions open · free to apply
Attended a masterclass or have a friend's referral code? You get ₹15,000 off. Fill this and our team takes it from here — pay by cash or online.