expertSecurity (Expert Round)

How do you prevent SSRF attacks in a microservice that fetches external URLs on a user's behalf?

Tests whether you know to allowlist domains and specifically block internal metadata IP ranges like 169.254.x.x.

Ready to master this question?

Generate a complete walkthrough — background, the full answer in plain language, a working code example explained line by line, a real-world scenario, common mistakes, and how this same question gets asked in different ways.

Sign in to generate a response

Next Step

Continue to Half your pods are running the new version and half are still on the old version, well after a rollout should have finished. What would you check?← Back to all Company Round Scenarios questions