Project Setup • Beans • REST Endpoints • JPA Basics • Your Projects • 2026

Spring Boot Interview Questions for Freshers

Spring Boot fresher rounds check whether you can explain the basics in your own words: what a bean is, how an app starts without a separate server, how a request reaches your controller, and how an entity becomes a table. Expect a small endpoint to write on a whiteboard and questions about the project you built in college. It is written for final-year students, new graduates and anyone coming out of an internship or a bootcamp who is facing a first Spring Boot interview. Each question shows what the interviewer is checking, the shape of a good answer and a short answer you can say out loud. Swap the project stories for your own.

Search all questions by round, difficulty and level, or save the ones you want to practice.

Beans & DI 4 questions

Easy Technical round Fresher Practice question

1. In simple words, what is the Spring container, and what makes an object a bean instead of a normal object you create with new?

What the interviewer is really testing:
Whether you understand inversion of control as an idea, not just as an annotation you copy, and can say who creates and owns the objects.
Answer frame:

The container: the ApplicationContext creates, wires and keeps your objects.

A bean: any object the container manages, found through annotations or @Bean methods.

Why it matters: you ask for what you need, and the container hands it over already built.

Sample spoken answer:

“The Spring container, the ApplicationContext, is basically an object factory that runs when the app starts. It scans my packages, finds classes marked with things like @Service or @Repository, creates one object for each, and connects them to each other. Each object it manages is called a bean. The difference from a normal object is ownership. If I write new StudentService myself, I have to create its repository too, and Spring knows nothing about it, so things like transactions won't work on it. If it's a bean, I just ask for it in a constructor and the container gives me a ready one. That's what inversion of control means: my code no longer controls creating its dependencies, the framework does.”

Red flag to avoid:

Saying a bean is just a Java class with getters and setters, which mixes it up with a JavaBean.

They may ask next:
  • If you create a service with new inside a controller, what stops working?
  • Where does the container look for classes to turn into beans?
Say it in 60 seconds
Hard Technical round Fresher, Mid-level Practice question

2. By default, how many objects of your @Service class does Spring create? What goes wrong if you store a counter or the current user in a field of that service?

What the interviewer is really testing:
Whether you connect the default singleton scope with many requests running at once, which separates a fresher who understands from one who memorised.
Answer frame:

One instance: singleton scope is the default, one object for the whole app.

Shared by threads: every request runs on its own thread and uses that same object.

The fix: keep services stateless; use local variables, method parameters or thread-safe types.

Sample spoken answer:

“By default Spring creates just one object of each bean, because singleton is the default scope. That one StudentService is shared by every request, and each request runs on its own thread from Tomcat's pool. So if I keep the current user in a field, two people logging in at the same moment can overwrite each other, and one might see the other's data. A counter in an int field has the same problem. count plus plus isn't atomic, so two threads can read the same value and one update gets lost. The fix is to keep services stateless: per-request data goes in local variables or method parameters. If I really need a shared counter, I'd use an AtomicInteger, or better, store it in the database.”

Red flag to avoid:

Saying Spring creates a new service object for every request.

They may ask next:
  • Is it safe to keep a repository reference in a field? Why?
  • When would you use request scope instead?
Say it in 60 seconds
Medium Technical round Fresher Practice question

3. You add a second class implementing NotificationService and the app stops starting with 'required a single bean, but 2 were found'. What does it mean, and how do you fix it?

What the interviewer is really testing:
Whether you can read a common startup error and know the tools for choosing between beans of the same type.
Answer frame:

The cause: injection is by type, and now two beans match.

@Primary: marks the default one when nobody asks for a specific bean.

@Qualifier: names the exact bean at the injection point; or inject a List of all of them.

Sample spoken answer:

“Spring injects by type. My controller asks for a NotificationService, and now there's an EmailNotificationService and an SmsNotificationService, both beans. Spring can't guess, so it refuses to start, which is better than silently picking one. There are a few fixes depending on what I want. If email is the normal choice, I put @Primary on that class, and anyone asking for the interface gets email. If one class really needs SMS, I add @Qualifier with the bean name, which by default is the class name starting with a small letter, so smsNotificationService. And if I want to send through every channel, I inject a List of NotificationService and Spring hands me all of them.”

Red flag to avoid:

Fixing it by deleting one class or by creating the object with new.

They may ask next:
  • What is the default name of a bean created from a class?
  • If both @Primary and @Qualifier are present, which one wins?
Say it in 60 seconds
Medium Technical round Fresher Practice question

4. When would you create a bean with a @Bean method in a @Configuration class instead of putting @Component on the class?

What the interviewer is really testing:
Whether you know the two ways to register a bean and the real reason the second one exists.
Answer frame:

@Component: for your own classes; Spring finds them by scanning.

@Bean: for classes you can't edit, like a library's, or that need setup code.

Example: a RestTemplate, an ObjectMapper or a password encoder.

Sample spoken answer:

“For my own classes I just add @Component or @Service and component scanning picks them up. But I can't put an annotation on a class from a library, like RestTemplate or BCryptPasswordEncoder, because I don't own that source code. That's where @Bean comes in. I write a method inside a class marked @Configuration, create and set up the object there, and return it. Spring calls the method once and registers the result as a bean, named after the method by default. It's also handy when building the object needs some logic, like setting timeouts or choosing between two implementations. In my project I had a @Bean method for the password encoder, and then any service could ask for a PasswordEncoder in its constructor.”

Code:
@Configuration
public class AppConfig {
    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }
}
Red flag to avoid:

Not knowing @Bean exists, or thinking you can annotate library classes.

They may ask next:
  • What's the bean's name when it comes from a @Bean method?
  • Could you put a @Bean method in a class with only @Component?
Say it in 60 seconds

Getting Started 4 questions

Easy Technical round Fresher Practice question

5. How would you create a brand new Spring Boot project? Walk me through what you choose and the folders you get.

What the interviewer is really testing:
Whether you have actually built a project yourself and know where things live, rather than only following a video.
Answer frame:

Initializr: build tool, Java version, group and artifact, and the dependencies you need.

What you get: main class, application.properties, a test folder and the build file.

Run it: the wrapper script or the IDE, then check the startup log.

Sample spoken answer:

“I use Spring Initializr, either the website or the one built into my IDE. I pick Maven or Gradle, the Java version, a group and artifact name, and add dependencies, usually Spring Web, Spring Data JPA, a database driver and Validation. It gives me a zip with a clear layout. Under src/main/java there's the main class with @SpringBootApplication and a main method. Under src/main/resources there's application.properties, plus static and templates folders if I'm serving pages. There's a matching src/test/java with one test that checks the context loads. At the top is the pom.xml and the Maven wrapper, so anyone can build it without installing Maven. I run it with the wrapper or from the IDE, and the log tells me Tomcat started on port 8080.”

Red flag to avoid:

Having no idea where configuration files go, or never having created a project from scratch.

They may ask next:
  • What does that one generated test actually prove when it passes?
  • What is the Maven wrapper for?
Say it in 60 seconds
Easy Technical round Fresher Practice question

6. How does a Spring Boot app run with just java -jar, without installing Tomcat separately? What is inside that jar?

What the interviewer is really testing:
Whether you know what an embedded server and an executable jar are, since that is the main practical difference from older Java web apps.
Answer frame:

Embedded server: the web starter brings Tomcat in as a normal library.

Executable jar: the build plugin packs your code and every dependency into one jar.

Contrast: older apps built a war and copied it into a Tomcat you installed yourself.

Sample spoken answer:

“When I add the web starter, Tomcat comes in as a regular dependency, just like any other library. So instead of my app being deployed into a server, the server lives inside my app. When main runs, Spring Boot starts that embedded Tomcat on port 8080 and registers my controllers with it. The Spring Boot Maven plugin then builds an executable jar, sometimes called a fat jar. It holds my compiled classes plus every dependency jar inside it, and a small launcher that knows how to load them. So java -jar is all you need on the machine, apart from Java itself. The old way was to build a war file and copy it into a Tomcat someone had installed and configured on the server.”

Red flag to avoid:

Thinking Tomcat must be installed on the machine, or not knowing what a jar contains.

They may ask next:
  • How would you switch from Tomcat to another embedded server?
  • Can you still build a war file with Spring Boot?
Say it in 60 seconds
Easy Technical round Fresher Practice question

7. How do you change the port your app runs on, and where do you put the database URL, username and password?

What the interviewer is really testing:
Whether you know the everyday properties by heart and understand that config lives outside the code.
Answer frame:

Port: server.port in application.properties or application.yml.

Database: the spring.datasource properties for URL, username and password.

Keep secrets out: real passwords come from environment variables, not the committed file.

Sample spoken answer:

“Both go in application.properties under src/main/resources. For the port I set server.port, say to 8081, if something else is already using 8080. For the database I set spring.datasource.url with the JDBC URL, then spring.datasource.username and spring.datasource.password. With the JPA starter I sometimes add spring.jpa.show-sql while learning, so I can see the SQL Hibernate runs. Spring Boot reads this file at startup and uses it to build things like the connection pool for me, so I don't write that code myself. One thing I learned in my project: the password shouldn't sit in a file that goes to GitHub. Spring Boot also reads environment variables, so for anything real the password comes from there and the file only has safe local values.”

Code:
server.port=8081
spring.datasource.url=jdbc:mysql://localhost:3306/college
spring.datasource.username=app_user
spring.datasource.password=local-only
spring.jpa.show-sql=true
Red flag to avoid:

Hard-coding the database URL and password inside a Java class.

They may ask next:
  • What's the difference between application.properties and application.yml?
  • How would you pass a different port when starting the jar?
Say it in 60 seconds
Easy Technical round Fresher Practice question

8. Your app won't start. The log says either 'Port 8080 was already in use' or 'Failed to configure a DataSource'. What does each mean, and how do you fix it?

What the interviewer is really testing:
Whether you read the startup log calmly and know the two errors nearly every beginner hits.
Answer frame:

Port in use: another process, often an old run of your own app, holds 8080.

DataSource: the JPA starter is present but no database URL or embedded database is set.

Habit: read the last error in the log first; it usually says the fix.

Sample spoken answer:

“The first one means something is already listening on 8080. Most of the time, for me, it was my own app still running from an earlier run in another terminal or IDE window. I either stop that process or change server.port to a free port. The second one appears when the Data JPA starter is on the classpath. Spring Boot then tries to set up a database connection, but it can't find spring.datasource.url and there's no embedded database like H2. The fix is to add the URL, username and password, or add H2 while I'm just learning. If I added JPA by accident and don't need a database yet, I remove that dependency. In both cases the log says what's wrong, usually near the bottom, so I read that before searching online.”

Red flag to avoid:

Restarting the laptop without reading the error, or not knowing where the log is.

They may ask next:
  • How would you find which process is using the port?
  • What is H2 and when would you use it?
Say it in 60 seconds

Web & REST 5 questions

Easy Technical round Fresher Practice question

9. What is the difference between @Controller and @RestController? When would you use each one?

What the interviewer is really testing:
Whether you know what the method's return value turns into in each case, which is the part freshers often get wrong.
Answer frame:
@Controller vs @RestController
@Controllerthe return value is a view name, rendered by a template engine.
@RestController@Controller plus @ResponseBody, so the return value is written as JSON.

When: server-rendered pages versus an API for a frontend or mobile app.

Sample spoken answer:

“With @Controller, a method usually returns a String, and Spring treats it as the name of a view. So returning home makes a template engine like Thymeleaf render home.html. @RestController is @Controller and @ResponseBody combined. Now whatever the method returns is written straight into the response body, and for an object that means Jackson turns it into JSON. In my college project the backend served a React frontend, so everything was @RestController and returned objects that became JSON. If I were building server-rendered pages, like an admin screen with forms, I'd use @Controller. You can also mix: a plain @Controller with @ResponseBody on one method returns data from just that method.”

Red flag to avoid:

Saying they are the same, or not knowing what @ResponseBody does.

They may ask next:
  • What happens if a @Controller method returns a String but no template has that name?
  • Which library turns your object into JSON?
Say it in 60 seconds
Easy Coding round Fresher Practice question

10. What's the difference between @PathVariable and @RequestParam? Show me both in one controller method.

What the interviewer is really testing:
Whether you can read a URL and say which part is which, and know what happens when a parameter is missing.
Answer frame:
@PathVariable vs @RequestParam
@PathVariablepart of the path itself, usually an id that names one resource.
@RequestParamthe query string after the question mark, often for filters or paging.

Missing values: request params are required by default; use required false or a default value.

Sample spoken answer:

“A path variable is part of the URL path, like the 42 in /students/42/courses. It usually identifies one thing. A request param comes from the query string after the question mark, like ?semester=5, and it's used for filtering, sorting or paging. In the method, @PathVariable binds the id from the path, and @RequestParam binds semester from the query. One detail people miss is that @RequestParam is required by default, so if the client leaves it out, Spring answers with 400 Bad Request. If it's optional, I either set required to false and accept a null, or give it a defaultValue. Spring also converts types for me, so the id arrives as a Long, and a value like abc gets a 400 instead of reaching my code.”

Code:
@GetMapping("/students/{id}/courses")
public List<CourseDto> courses(@PathVariable Long id,
                               @RequestParam(defaultValue = "1") int semester) {
    return courseService.findForStudent(id, semester);
}
Red flag to avoid:

Swapping the two, or not knowing that a missing required param returns 400.

They may ask next:
  • If the variable name in the path differs from the method parameter, how do you connect them?
  • Would you put a password in a request param? Why not?
Say it in 60 seconds
Easy Coding round Fresher Practice question

11. Sketch a controller for a Student resource with create, read, update and delete. Which HTTP method and status code goes with each?

What the interviewer is really testing:
Whether you know the REST conventions most fresher projects use and can write the mapping annotations without looking them up.
Answer frame:

Base path: @RequestMapping on the class, plural noun like /students.

Four verbs: GET to read, POST to create, PUT to replace, DELETE to remove.

Status codes: 200 for reads and updates, 201 for create, 204 for delete with no body.

Sample spoken answer:

“I put @RestController and @RequestMapping("/students") on the class so every method shares the base path. GET on /students lists them and GET on /students/{id} fetches one, both returning 200. POST on /students creates a student from the JSON body, and I return 201 Created, because that tells the client something new exists. PUT on /students/{id} replaces that student's details and returns 200 with the updated record. DELETE on /students/{id} removes it and returns 204 No Content, since there's nothing to send back. The controller stays thin: each method just calls the service. If an id doesn't exist, the right answer is 404, which I'd handle with an exception mapped to that status rather than returning null.”

Code:
@RestController
@RequestMapping("/students")
public class StudentController {
    private final StudentService service;
    public StudentController(StudentService service) { this.service = service; }

    @GetMapping("/{id}")
    public StudentDto get(@PathVariable Long id) { return service.get(id); }

    @PostMapping
    @ResponseStatus(HttpStatus.CREATED)
    public StudentDto create(@RequestBody StudentDto dto) { return service.create(dto); }

    @PutMapping("/{id}")
    public StudentDto update(@PathVariable Long id, @RequestBody StudentDto dto) {
        return service.update(id, dto);
    }

    @DeleteMapping("/{id}")
    @ResponseStatus(HttpStatus.NO_CONTENT)
    public void delete(@PathVariable Long id) { service.delete(id); }
}
Red flag to avoid:

Using GET for everything, or returning 200 with an error message inside the body.

They may ask next:
  • What's the difference between PUT and PATCH?
  • Why is GET supposed to have no side effects?
Say it in 60 seconds
Medium Coding round Fresher Practice question

12. Write a GET endpoint that fetches a student by id and returns 404 Not Found when the id doesn't exist, not a 500.

What the interviewer is really testing:
Whether you know ResponseEntity and Optional well enough to control the status code, instead of letting a null crash the request.
Answer frame:

findById: returns an Optional, never null.

ResponseEntity: lets you choose the status and body in the method.

Map or else: found becomes 200 with the body, empty becomes 404.

Sample spoken answer:

“The repository's findById gives me an Optional, so I don't need a null check. I map the found student to a DTO wrapped in ResponseEntity.ok, which is a 200 with that body. If the Optional is empty, orElse gives back ResponseEntity.notFound().build(), which is a 404 with no body. The mistake I made early on was calling get on the Optional directly. When the id didn't exist it threw an exception and the client got a 500, which wrongly says the server broke. Another clean way is to throw ResponseStatusException with NOT_FOUND, or a custom exception that a global handler maps to 404. I'd use that once the app has many endpoints, so every missing record looks the same.”

Code:
@GetMapping("/students/{id}")
public ResponseEntity<StudentDto> getStudent(@PathVariable Long id) {
    return studentRepository.findById(id)
            .map(s -> ResponseEntity.ok(StudentDto.from(s)))
            .orElse(ResponseEntity.notFound().build());
}
Red flag to avoid:

Calling Optional.get without checking, or returning 200 with a null body.

They may ask next:
  • Why is a 500 the wrong answer for a missing record?
  • When would you throw an exception instead of returning ResponseEntity?
Say it in 60 seconds
Hard Technical round Fresher, Mid-level Practice question

13. You want to log every request's URL and how long it took. Would you use a servlet Filter or a Spring HandlerInterceptor, and what's the difference?

What the interviewer is really testing:
Whether you know where a request passes before reaching your controller, which shows understanding beyond writing endpoints.
Answer frame:

Filter: servlet level, runs before Spring MVC, sees every request.

Interceptor: inside Spring MVC, runs around the controller method and knows which handler it is.

Choice: a filter for all traffic; an interceptor when you need controller details.

Sample spoken answer:

“A Filter belongs to the servlet layer. It runs before the request even reaches Spring's DispatcherServlet, so it sees everything, including requests that never match a controller. A HandlerInterceptor lives inside Spring MVC. It runs after the DispatcherServlet has picked the controller method, with preHandle before the method and afterCompletion once the request is done, and it knows which handler was chosen. For timing every request, I'd use a filter. I note the time, call chain.doFilter to let the request go through, then log the URL, status and time taken. If I needed to know which controller method handled it, or I wanted to check something only for certain endpoints, I'd pick an interceptor and register it through WebMvcConfigurer. Spring Security itself is built on filters, which is why it can block a request before any controller runs.”

Red flag to avoid:

Saying they are the same thing, or putting the timing code inside every controller method.

They may ask next:
  • How do you register an interceptor for only some URL paths?
  • If the controller throws an exception, does the filter still get to log the time?
Say it in 60 seconds

Data & JPA 3 questions

Easy Coding round Fresher Practice question

14. Write a simple JPA entity for a Student. What do @Entity, @Id, @GeneratedValue and @Column each do?

What the interviewer is really testing:
Whether you understand how a Java class maps to a database table, which almost every fresher project relies on.
Answer frame:

@Entity: this class maps to a table; it needs a no-argument constructor.

@Id and @GeneratedValue: the primary key, and who creates its value.

@Column: column name and rules such as not null or unique.

Sample spoken answer:

“@Entity tells JPA that this class maps to a table, by default one named after the class. Every entity needs a primary key, marked with @Id. @GeneratedValue says I won't set the id myself. With the IDENTITY strategy the database creates it, like an auto-increment column in MySQL. @Column is optional, since every field maps to a column anyway, but I use it to set rules, like nullable false for the name or unique true for the email. JPA also needs a no-argument constructor, because Hibernate creates the object first and then fills in the fields from the row. In my project I used jakarta.persistence imports, since newer Spring Boot versions moved from javax to jakarta.”

Code:
@Entity
public class Student {
    @Id
    @GeneratedValue(strategy = GenerationType.IDENTITY)
    private Long id;

    @Column(nullable = false)
    private String name;

    @Column(unique = true)
    private String email;

    protected Student() { } // required by JPA

    public Student(String name, String email) {
        this.name = name;
        this.email = email;
    }
}
Red flag to avoid:

Forgetting the primary key, or thinking @Column is required on every field.

They may ask next:
  • How would you map a field you don't want saved in the table?
  • How would you map a Student who has many Courses?
Say it in 60 seconds
Hard Technical round Fresher, Mid-level Practice question

15. You write StudentRepository as an interface extending JpaRepository and never write a class for it. So where does the code that runs save and findAll come from?

What the interviewer is really testing:
Whether you are curious about what happens behind the magic: a strong fresher knows Spring builds a proxy for the interface at startup.
Answer frame:

What you inherit: save, findById, findAll, deleteById, count, paging and sorting.

Who implements it: Spring Data creates a proxy object for the interface at startup.

Where the work goes: standard calls go to a built-in implementation backed by JPA.

Sample spoken answer:

“Extending JpaRepository with the entity type and id type gives me a set of ready methods: save, findById, findAll, deleteById, count, existsById, plus paging and sorting. I never write the class because Spring Data writes it for me at runtime. At startup it finds every repository interface and creates a proxy object that implements it, then registers that proxy as a bean. When I call save, the proxy passes it to a built-in class, SimpleJpaRepository, which uses the JPA EntityManager underneath. For custom method names, the proxy has already worked out the query from the name when the app started, which is why a typo in a method name makes startup fail instead of failing later. So when I inject StudentRepository into a service, I'm really getting that generated proxy.”

Red flag to avoid:

Saying Spring generates Java source files, or having no idea and calling it magic.

They may ask next:
  • What's the difference between CrudRepository and JpaRepository?
  • Why does findById return an Optional?
Say it in 60 seconds
Medium Technical round Fresher Practice question

16. In plain words, what does @Transactional do? Explain it with a fee payment or a money transfer between two accounts.

What the interviewer is really testing:
Whether you understand all-or-nothing as an idea, and know where the annotation belongs, before you are asked about its traps.
Answer frame:

All or nothing: every database change in the method commits together or none do.

Example: debit one account, credit another; a failure between them must undo the debit.

Where it goes: the service method, and the default rollback rule.

Sample spoken answer:

“@Transactional means all the database work inside the method happens as one unit. Take a transfer: I take money from account A and add it to account B. If the code fails after the debit but before the credit, without a transaction A has lost money and B got nothing. With @Transactional on the service method, Spring starts a transaction before the method runs and commits when it returns normally. If a runtime exception escapes, it rolls everything back, so A's balance goes back too. I put it on the service layer, because that's where one business action might touch several tables. One thing I know to watch: by default it rolls back on unchecked exceptions, not checked ones, unless you say so with rollbackFor.”

Red flag to avoid:

Thinking it makes a method thread-safe, or that it has something to do with network requests.

They may ask next:
  • Why put it on the service and not on the controller?
  • What does ACID stand for?
Say it in 60 seconds

App Structure 2 questions

Easy Technical round Fresher Practice question

17. Explain the controller, service and repository layers using your own project. Why not just put everything in the controller?

What the interviewer is really testing:
Whether you designed your project in layers on purpose and can explain what each layer is responsible for.
Answer frame:

Controller: HTTP only; reads the request, calls the service, returns the response.

Service: the business rules and transactions.

Repository: talks to the database; nothing else does.

Sample spoken answer:

“In my hostel booking project, the BookingController only dealt with HTTP. It read the room id and dates from the request and returned the right status. The BookingService held the rules: a student can't book two rooms for the same dates, and a room can't be over capacity. It was also where I put @Transactional. The BookingRepository only talked to the database. Keeping them apart helped in two ways. When we added a mobile screen that booked rooms in a slightly different flow, the rules were already in one place, so we didn't copy them. And testing the service was easy: I could mock the repository and check the rules without starting a server or a database. When it was all in the controller early on, one method was over a hundred lines.”

Red flag to avoid:

Putting business rules in the controller, or saying layers exist only because tutorials use them.

They may ask next:
  • Where would you put input validation?
  • Should a controller ever call a repository directly?
Say it in 60 seconds
Medium Technical round Fresher, Mid-level Practice question

18. Why do many projects return a DTO from the controller instead of the JPA entity itself?

What the interviewer is really testing:
Whether you see the API and the database table as two different things, and know the real bugs that come from mixing them.
Answer frame:

Hide fields: entities often hold data the client must not see, like a password hash.

Avoid JSON trouble: lazy relations and two-way links break or loop during serialization.

Freedom: the table can change without breaking the API.

Sample spoken answer:

“A DTO is a simple class, often a Java record, shaped for what the API should send. The first reason is safety. My User entity had a password hash field, and returning the entity would have sent it to the browser. The second reason is that entities cause JSON trouble. In my project, Student had a list of Courses and Course pointed back to Students. When I returned the entity, Jackson went back and forth between them until it failed with a stack overflow. Lazy relations can also throw errors when they're read outside a transaction. The third is freedom: if I rename a column or split a table, the DTO keeps the API the same for the frontend. It costs a bit of mapping code, but that's worth it.”

Red flag to avoid:

Saying DTOs are just extra boilerplate with no purpose.

They may ask next:
  • Where would you do the mapping between the entity and the DTO?
  • Why is a Java record a good fit for a DTO?
Say it in 60 seconds

Security & Testing 2 questions

Medium Technical round Fresher Practice question

19. Your project has a sign-up and login page. How would you store user passwords, and what does Spring Security give you for it?

What the interviewer is really testing:
Whether you know never to store plain text passwords, and understand hashing with a salt at a basic level.
Answer frame:

Never plain text: store a one-way hash, not the password or an encrypted version.

BCrypt: slow on purpose, with a random salt built in; Spring gives you BCryptPasswordEncoder.

Checking: matches compares the typed password against the stored hash.

Sample spoken answer:

“I'd never store the password itself. I'd store a hash, which is a one-way scramble that can't be turned back into the password. Spring Security has a PasswordEncoder interface, and I'd use BCryptPasswordEncoder. On sign-up, I call encode on the password and save the result. BCrypt adds a random salt each time, so two users with the same password get different hashes, and it's deliberately slow, which makes guessing millions of passwords expensive. On login I don't hash and compare strings myself. I call matches with the typed password and the stored hash, and it handles the salt. In my first project I stored plain text and only fixed it when a senior pointed it out, so this is something I now do from the first day.”

Red flag to avoid:

Saying you'd encrypt the password so you can decrypt it later, or storing plain text.

They may ask next:
  • Why is a fast hash like MD5 a bad choice for passwords?
  • What happens when you add the Spring Security starter and change nothing else?
Say it in 60 seconds
Medium Coding round Fresher Practice question

20. How would you write a unit test for a service method without starting Spring or a real database?

What the interviewer is really testing:
Whether you have written real tests and know how mocking lets you test one class alone.
Answer frame:

Mock the repository: Mockito gives a fake whose answers you control.

Real service: create it with the mock passed into its constructor.

Check the result: assert the happy path and the error path.

Sample spoken answer:

“Because my service takes its repository through the constructor, I don't need Spring at all. With JUnit 5 and Mockito, I mark the repository with @Mock and the service with @InjectMocks, and Mockito builds the service with the fake repository inside. Then I tell the mock what to return, for example that findById for id 7 returns an empty Optional. I call the service method and check it throws my StudentNotFoundException. A second test returns a real student and checks the DTO has the right name. These tests run in milliseconds, since no application context or database starts. I'd save the slower @SpringBootTest style for checking that the pieces work together.”

Code:
@ExtendWith(MockitoExtension.class)
class StudentServiceTest {
    @Mock StudentRepository repository;
    @InjectMocks StudentService service;

    @Test
    void throwsWhenStudentMissing() {
        when(repository.findById(7L)).thenReturn(Optional.empty());
        assertThrows(StudentNotFoundException.class, () -> service.get(7L));
    }
}
Red flag to avoid:

Saying every test needs @SpringBootTest, or never having written a test.

They may ask next:
  • How would you check that the service called save exactly once?
  • Why does constructor injection make this test easier?
Say it in 60 seconds

Projects 3 questions

Medium Behavioral round Fresher Practice question

21. Walk me through a Spring Boot project you built in college or during an internship. What did you build yourself, and what would you do differently now?

What the interviewer is really testing:
Whether you really built what is on your resume, can separate your part from the team's, and have learned since.
Answer frame:

What and why: the problem in one line, and the main parts of the app.

Your part: the endpoints, tables or features you wrote yourself.

Looking back: one honest thing you would change and why.

Sample spoken answer:

“In my final year, three of us built a canteen pre-order app. Students ordered from their phones and the canteen saw orders on a screen. The backend was Spring Boot with MySQL, and the frontend was React. I owned the backend: the entities for menu items, orders and order lines, the REST endpoints, and the rule that an order closes fifteen minutes before pickup. I also wrote the login using Spring Security and BCrypt. What I'd do differently is that I returned entities straight from the controllers, and we hit an infinite JSON loop between Order and OrderLine. I patched it with an annotation. Now I'd use DTOs from the start. I'd also write tests earlier, because we found most bugs during the demo week.”

Red flag to avoid:

Describing the team's work as all yours, or being unable to explain code you listed on your resume.

They may ask next:
  • What was the hardest bug in that project, and how did you find it?
  • If a thousand students ordered at lunch, which part would break first?
Say it in 60 seconds
Easy Behavioral round Fresher Practice question

22. Tell me about a time you were stuck on a Spring Boot error during a project, a lab or an internship. How did you get unstuck?

What the interviewer is really testing:
Whether you debug with a method, reading logs and narrowing things down, rather than copying random fixes until it works.
Answer frame:

The error: what you saw, in one or two lines.

The method: read the full stack trace, form a guess, test it small.

The lesson: what you do differently since.

Sample spoken answer:

“In my final-year project, my POST endpoint for adding a student returned 200, but every row in the table had a null name and email. There was no error at all, which made it confusing. I first blamed the database mapping and spent a while changing column annotations, which was a waste. Then I stopped guessing and put a breakpoint on the first line of the controller method. The DTO was already empty there, so the database was never the problem. That narrowed it to how the request was read. I'd forgotten @RequestBody on the parameter, so Spring tried to fill the object from query parameters and simply ignored the JSON body. I added it and it worked. What I took from it is to find where the data goes wrong before changing anything, and I now test new endpoints with a real request straight away.”

Red flag to avoid:

A story where the fix was pasted from a forum without knowing why it worked.

They may ask next:
  • How do you decide when to ask a senior for help instead of trying longer?
  • How would you stop an empty name from being saved even when the JSON is read correctly?
Say it in 60 seconds
Medium Situational round Fresher Practice question

23. In a group project, a teammate commits application.properties with the real database password to a public GitHub repo. What do you do?

What the interviewer is really testing:
Whether you know that deleting the line is not enough, and can handle a mistake with a teammate calmly.
Answer frame:

Treat it as leaked: change the password first, because git history keeps the old one.

Fix the setup: read secrets from environment variables and keep local files out of git.

Handle the person: tell them privately and fix the process, not the blame.

Sample spoken answer:

“First I'd treat the password as already leaked. Even if we delete the line in the next commit, it stays in the git history, and public repos get scanned by bots quickly. So the first step is to change the database password. Then I'd fix the setup so it can't happen again. The committed properties file only has safe local values, and the real password comes from an environment variable, which Spring Boot reads at startup. I'd add a local properties file to .gitignore for anyone who prefers a file. I'd message the teammate privately and keep it light, because I've nearly done the same thing. Then I'd suggest the whole group check the repo for other keys, like an email or cloud key.”

Red flag to avoid:

Only deleting the line and moving on, or calling out the teammate in the group chat.

They may ask next:
  • Why isn't deleting the line in a new commit enough?
  • How does Spring Boot map an environment variable to a property name?
Say it in 60 seconds
Were you asked something else? Share it A person checks every question before it goes on the site. No name is shown.
For the call itself

You practiced these. On the real call, ClapAssist helps with the rest.

ClapAssist is an AI interview assistant for Mac and Windows. It listens to the interview on your computer and shows you what to say, in short lines you can read while you talk. Your live interview audio and screen are never stored. Your resume and notes are saved to your account so the app fills them in on any computer. It stays out of screen share on every plan, including Free; only you can see it.

Download with 10 free minutes
Mac and Windows · Stays out of screen share · No card