Backend Interview Preparation
Backend Interview Preparation
Backend developer interviews test multiple dimensions: your technical knowledge, your ability to write code under pressure, your system design thinking, and your communication skills. Understanding what each stage looks like lets you prepare effectively.
Types of Backend Interviews
1. Technical Phone Screen
A 30-60 minute call covering:
- Your background and experience
- 1-2 conceptual questions ("Explain how JWT works")
- Sometimes a small coding problem on a shared editor
2. Take-Home Project
You are given 3-7 days to build a small backend feature or API. Companies use this to see real code quality, organisation, and documentation. Treat it like a portfolio project.
3. Live Coding Interview
You write code in real time while an interviewer watches. This tests problem-solving process, not just answers. Think out loud — interviewers want to hear your reasoning.
4. System Design Interview
You design a system on a whiteboard or virtual diagram tool. Common at mid-to-senior level. "Design a URL shortener like bit.ly" or "Design Paystack's payment processing system."
Common Technical Questions and Model Answers
Q: What is the difference between authentication and authorisation?
Authentication verifies who you are (login, identity). Authorisation determines what you are allowed to do (permissions, roles). Authentication always precedes authorisation. 401 is for unauthenticated requests; 403 is for authenticated but unauthorised.
Q: How does JWT authentication work?
The server signs a JSON Web Token containing the user's ID and role using a secret key. The client stores the token and sends it in the Authorization header on every request. The server verifies the signature on each request — no database lookup needed, making it stateless and scalable.
Q: What is the difference between SQL and NoSQL databases?
SQL databases like PostgreSQL use structured tables with a fixed schema and enforce relationships with foreign keys. NoSQL databases like MongoDB store flexible JSON documents in collections. SQL is better for complex relationships and transactions; NoSQL is better for flexible schemas and horizontal scaling.
Q: How do you prevent SQL/NoSQL injection?
For MongoDB: use express-mongo-sanitize to strip query operators from user input, and use Mongoose's type system which parameterises queries. Never concatenate user input directly into queries.
Q: Explain REST API design principles.
REST uses standard HTTP methods (GET, POST, PUT, PATCH, DELETE) on resource-oriented URLs (plural nouns like /users, /products). It is stateless — no session data on the server. Responses use consistent JSON structures with appropriate HTTP status codes.
Data Structures for Backend Interviews
Backend interviews sometimes include algorithmic questions. The most commonly tested data structures:
Hash Maps / Objects: O(1) average lookup. Used for caching, counting, and deduplication.
// Count word frequency
function wordCount(text) {
const counts = {};
for (const word of text.split(' ')) {
counts[word] = (counts[word] || 0) + 1;
}
return counts;
}
Queues: First-In-First-Out (FIFO). Used for job queues, BFS (Breadth-First Search), and rate limiting.
// Simple queue with array
const queue = [];
queue.push('job1');
queue.push('job2');
const next = queue.shift(); // 'job1'
Binary Search: O(log n) search in a sorted array.
function binarySearch(arr, target) {
let lo = 0, hi = arr.length - 1;
while (lo <= hi) {
const mid = Math.floor((lo + hi) / 2);
if (arr[mid] === target) return mid;
else if (arr[mid] < target) lo = mid + 1;
else hi = mid - 1;
}
return -1;
}
Big O Notation
Big O describes how a function's performance scales with input size. You need a working knowledge for interviews:
| Notation | Name | Example |
|---|---|---|
| O(1) | Constant | Hash map lookup |
| O(log n) | Logarithmic | Binary search |
| O(n) | Linear | Loop through array |
| O(n log n) | Log-linear | Efficient sorting |
| O(n²) | Quadratic | Nested loops |
Live Coding Tips
- Clarify before coding — ask about input format, edge cases, expected output
- Think out loud — narrate your approach as you work
- Start with a working solution, then optimise — a slow correct answer beats a fast broken one
- Test with examples — run through 1-2 inputs manually after writing the code
- Name things clearly —
userEmailnotue
Key Takeaways
- Backend interviews cover four areas: phone screen, take-home project, live coding, and system design.
- Prepare model answers for: JWT, REST, SQL vs NoSQL, authentication vs authorisation, and common security topics.
- Know the basics of hash maps, queues, binary search, and Big O notation.
- In live coding, think out loud — interviewers want to understand how you think, not just what you produce.
- Treat take-home projects like portfolio work — clean code, a good README, and a deployed URL.
Practice Exercise
- Answer these questions out loud, timing yourself at 2 minutes each:
- "How does JWT authentication work?"
- "What is the difference between SQL and NoSQL?"
- "How would you design a rate limiter?"
- Solve this problem: given an array of integers, return all pairs that sum to a target value. Aim for O(n) using a hash map.
- Find a take-home challenge online (many companies post them publicly) and complete it within the stated time limit.
Try it yourself
Key Takeaways
- Backend interviews typically include a phone screen, take-home project, live coding, and system design — prepare for all four.
- Prepare clear 2-minute answers for JWT, REST, SQL vs NoSQL, authentication vs authorisation, and security topics.
- In live coding, clarify the problem and think out loud — the process matters as much as the solution.
- Know Big O notation for common operations: O(1) for hash maps, O(log n) for binary search, O(n) for loops.
- Treat take-home projects as portfolio pieces — clean code, a README, and a deployed URL will stand out.
Quick Quiz
1.What is the purpose of a take-home project in a backend interview process?
2.What is the time complexity of a hash map lookup?
3.What should you do before writing any code in a live coding interview?
4.What HTTP status code should you return when a user is logged in but tries to access a resource they do not have permission for?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx